|
Message-ID: <SJ0PR11MB500698A24AD3AC00A44358D7DCC29@SJ0PR11MB5006.namprd11.prod.outlook.com> Date: Thu, 5 May 2022 01:50:08 +0000 From: "Jiang, Cheng1" <cheng1.jiang@...el.com> To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com> Subject: DPDK CVE-2021-3839 Release Notice A vulnerability was fixed in DPDK. Some downstream stakeholders were warned in advance in order to coordinate the release of fixes and reduce the vulnerability window. In DPDK Vhost communication, we didn't test if msg->payload.inflight.num_queues is out of bounds in function 'vhost_user_set_inflight_fd()', and could cause the program to write OOB. Commits: 6442c329b9d2 on the main branch CVE: CVE-2021-3839 Bugzilla: https://bugs.dpdk.org/show_bug.cgi?id=657 Severity: 5.2 (Medium) CVSS scores: 3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L Thanks Cheng Jiang, on behalf of the DPDK security team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.