An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
CVSS Details
- CVSS 3.0 Base Score: 7.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade dpdk-develUpgrade dpdkUpgrade dpdk-docUpgrade dpdk-tools | Jan 13, 2025 | Dec 18, 2024 |
| Debian | — | Upgrade dpdk | Dec 19, 2024 | Dec 19, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade dpdk | Feb 11, 2025 | Dec 18, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade dpdkUpgrade dpdk-toolsUpgrade dpdk-devel | Mar 19, 2025 | Dec 18, 2024 |
| Oracle_linux | — | Upgrade dpdk-docUpgrade dpdk-toolsUpgrade dpdkUpgrade dpdk-devel | Jan 10, 2025 | Dec 17, 2024 |
| Redhat_linux | — | Upgrade dpdk-toolsUpgrade dpdk-docUpgrade dpdk-debuginfoUpgrade dpdkUpgrade dpdk-develUpgrade dpdk-debugsource | Jan 10, 2025 | Dec 18, 2024 |
| Rocky_linux | — | Upgrade dpdk-debuginfoUpgrade dpdkUpgrade dpdk-debugsourceUpgrade dpdk-toolsUpgrade dpdk-devel | Jan 13, 2025 | Dec 18, 2024 |
| Suse | — | Upgrade dpdk-docUpgrade dpdk-thunderx-kmp-defaultUpgrade dpdk-toolsUpgrade dpdk-thunderx-examplesUpgrade dpdk-thunderxUpgrade dpdk-thunderx-devel-staticUpgrade dpdk-develUpgrade dpdk-thunderx-docUpgrade dpdk-devel-staticUpgrade dpdkUpgrade libdpdk-25Upgrade libdpdk-23Upgrade dpdk-thunderx-develUpgrade dpdk-thunderx-toolsUpgrade dpdk-kmp-defaultUpgrade dpdk-examples | Jan 9, 2025 | Dec 18, 2024 |
| Ubuntu | — | Upgrade dpdk | Dec 20, 2024 | Dec 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub