← Back

CVE-2018-1059

nvd nist
Published: Apr 24, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 4.0
Source: NVD

Description

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

Affected (15)

1 product
Ubuntu Linux
7 products
Ceph Storage
Enterprise Linux
Enterprise Linux Fast Datapath
Openshift
Openstack
Virtualization
Virtualization Manager
1 product
Data Plane Development Kit
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 17.10
Version 18.04
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Version 3.0
Version 7.0
Version 7.0
Version 3.0
Redhat
Version 10
Version 11
Version 12
Version 8
Version 9
Redhat
Version 4.0
Version 4.1
Version 4.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 18.02.1

References (16)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.