An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
History

Wed, 18 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Dec 2024 09:30:00 +0000

Type Values Removed Values Added
References

Wed, 18 Dec 2024 08:45:00 +0000

Type Values Removed Values Added
Title dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:7::fastdatapath
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:8::fastdatapath
cpe:/o:redhat:enterprise_linux:9
cpe:/o:redhat:enterprise_linux:9::fastdatapath
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References

Wed, 18 Dec 2024 01:45:00 +0000

Type Values Removed Values Added
Description An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
Title dpdk: Denial Of Service from malicious guest on hypervisors using DPDK Vhost library
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

threat_severity

Important


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-12-18T08:30:49.729Z

Updated: 2024-12-18T14:48:14.956Z

Reserved: 2024-11-22T04:21:45.124Z

Link: CVE-2024-11614

cve-icon Vulnrichment

Updated: 2024-12-18T09:03:01.520Z

cve-icon NVD

Status : Received

Published: 2024-12-18T09:15:06.660

Modified: 2024-12-18T09:15:06.660

Link: CVE-2024-11614

cve-icon Redhat

Severity : Important

Publid Date: 2024-12-17T00:00:00Z

Links: CVE-2024-11614 - Bugzilla