Description
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Published: 2026-09-08
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

A flaw was discovered in the DPDK vhost implementation, where the virtio‑net control‑queue handler reads command_data without validating the length. This omission results in an out‑of‑bounds read (CWE‑125) that can crash the host process. The crash does not expose sensitive data or allow remote code execution, but it disrupts the network interface and can lead to denial‑of‑service for services relying on the affected virtual network device.

Affected Systems

Red Hat Fast Datapath for RHEL 8, 9, 10, Red Hat Enterprise Linux 8, 9, 10, and Red Hat OpenShift Container Platform 4 are listed as affected. Specific version information is not provided, so any build that incorporates the vulnerable DPDK vhost code may be susceptible.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity. EPSS is not available and the vulnerability is not in CISA’s KEV catalog. Exploitation would likely require an attacker who can send malformed virtio‑net control‑queue commands to a host, such as a compromised or untrusted virtual machine. The affected component is a kernel‑space driver, so privileges may be limited to the virtualized environment. While the crash limits the impact to service disruption, any environment that relies on the affected Fast Datapath offers a potential target for DoS. There is no official patch or workaround yet, so operators should monitor vendor advisories for updates and consider temporary isolation strategies.

Generated by OpenCVE AI on September 9, 2026 at 08:50 UTC.

Remediation

Vendor Workaround

No mitigation is currently available.


OpenCVE Recommended Actions

  • Monitor Red Hat advisories and security releases for a patch affecting Fast Datapath and DPDK vhost.
  • If not immediately available, isolate or quarantine the virtual network interface that uses the vulnerable driver to prevent compromised guests from sending malformed control‑queue commands.
  • For multi‑tenant or high‑availability workloads, configure the virtualization layer to restrict or reject untrusted guest access to the virtio‑net control‑queue, even if supportive features are not fully documented.

Generated by OpenCVE AI on September 9, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Tue, 08 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Title Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-125
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:10::fastdatapath
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:8::fastdatapath
cpe:/o:redhat:enterprise_linux:9
cpe:/o:redhat:enterprise_linux:9::fastdatapath
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-09T13:14:26.786Z

Reserved: 2026-09-08T02:56:29.311Z

Link: CVE-2026-86564

cve-icon Vulnrichment

Updated: 2026-09-09T13:14:21.431Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T23:17:30.083

Modified: 2026-09-09T15:44:42.450

Link: CVE-2026-86564

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T00:00:00Z

Links: CVE-2026-86564 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T09:00:11Z

Weaknesses