ZeroHour

CVE-2018-1059

CVSS 3.0
6.1 medium
EPSS
<1%p56
Published
()
Modified
Description

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

Vendors
canonicalredhatdpdk
Products
ubuntu linux, ceph storage, enterprise linux fast datapath, openshift, openstack, virtualization, virtualization manager, enterprise linux, data plane development kit
Weakness
CWE-200
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.