CVE-2018-1059
6.1
Vector
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 1.6 / Impact: 4.0
Source: NVD
Description
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
Affected (15)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 17.10 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 | |
| Version 7.0 | |
| Version 7.0 | |
| Version 3.0 | |
| Version 10 | |
| Version 4.0 | |
| Version 4.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 18.02.1 |
References (16)
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Timeline
No history available yet.