CVE-2024-11614
Dpdk: denial of service from malicious guest on hypervisors using dpdk vhost library
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Productos afectados
dpdkRed Hat · Fast Datapath for Red Hat Enterprise Linux 8Red Hat · Fast Datapath for Red Hat Enterprise Linux 9Red Hat · Fast Datapath for RHEL 7Red Hat · Fast Datapath for RHEL 8Red Hat · Fast Datapath for RHEL 9Red Hat · Red Hat Enterprise Linux 8Red Hat · Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRed Hat · Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRed Hat · Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 8.8 Extended Update SupportRed Hat · Red Hat Enterprise Linux 9Red Hat · Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRed Hat · Red Hat Enterprise Linux 9.2 Extended Update SupportRed Hat · Red Hat Enterprise Linux 9.4 Extended Update SupportRed Hat · Red Hat OpenShift Container Platform 4¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2025:0208https://access.redhat.com/errata/RHSA-2025:0209https://access.redhat.com/errata/RHSA-2025:0210https://access.redhat.com/errata/RHSA-2025:0211https://access.redhat.com/errata/RHSA-2025:0220https://access.redhat.com/errata/RHSA-2025:0221https://access.redhat.com/errata/RHSA-2025:0222https://access.redhat.com/errata/RHSA-2025:3963https://access.redhat.com/errata/RHSA-2025:3964https://access.redhat.com/errata/RHSA-2025:3965https://access.redhat.com/errata/RHSA-2025:3970https://access.redhat.com/security/cve/CVE-2024-11614