A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
2022-08-23T16:15:10.087
2024-11-21T06:22:36.400
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | dpdk | data_plane_development_kit | < 22.03 | Yes |
| Application | dpdk | data_plane_development_kit | 22.03 | Yes |
| Application | dpdk | data_plane_development_kit | 22.03 | Yes |
| Application | dpdk | data_plane_development_kit | 22.03 | Yes |
| Operating System | fedoraproject | fedora | 35 | Yes |
| Operating System | redhat | enterprise_linux | 7.0 | Yes |
| Operating System | redhat | enterprise_linux | 8.0 | Yes |
| Operating System | redhat | enterprise_linux | 9.0 | Yes |
| Application | redhat | enterprise_linux_fast_datapath | 7.0 | Yes |
| Application | redhat | enterprise_linux_fast_datapath | 8.0 | Yes |