An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
Metrics
Affected Vendors & Products
References
History
Wed, 18 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 18 Dec 2024 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 18 Dec 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library | Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library |
First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:7::fastdatapath cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:8::fastdatapath cpe:/o:redhat:enterprise_linux:9 cpe:/o:redhat:enterprise_linux:9::fastdatapath |
|
Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
References |
|
Wed, 18 Dec 2024 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset. | |
Title | dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library | |
Weaknesses | CWE-125 | |
References |
| |
Metrics |
threat_severity
|
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2024-12-18T08:30:49.729Z
Updated: 2024-12-18T14:48:14.956Z
Reserved: 2024-11-22T04:21:45.124Z
Link: CVE-2024-11614
Vulnrichment
Updated: 2024-12-18T09:03:01.520Z
NVD
Status : Received
Published: 2024-12-18T09:15:06.660
Modified: 2024-12-18T09:15:06.660
Link: CVE-2024-11614
Redhat