Impact
A flaw was discovered in the DPDK vhost implementation, where the virtio‑net control‑queue handler reads command_data without validating the length. This omission results in an out‑of‑bounds read (CWE‑125) that can crash the host process. The crash does not expose sensitive data or allow remote code execution, but it disrupts the network interface and can lead to denial‑of‑service for services relying on the affected virtual network device.
Affected Systems
Red Hat Fast Datapath for RHEL 8, 9, 10, Red Hat Enterprise Linux 8, 9, 10, and Red Hat OpenShift Container Platform 4 are listed as affected. Specific version information is not provided, so any build that incorporates the vulnerable DPDK vhost code may be susceptible.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity. EPSS is not available and the vulnerability is not in CISA’s KEV catalog. Exploitation would likely require an attacker who can send malformed virtio‑net control‑queue commands to a host, such as a compromised or untrusted virtual machine. The affected component is a kernel‑space driver, so privileges may be limited to the virtualized environment. While the crash limits the impact to service disruption, any environment that relies on the affected Fast Datapath offers a potential target for DoS. There is no official patch or workaround yet, so operators should monitor vendor advisories for updates and consider temporary isolation strategies.
OpenCVE Enrichment