A vulnerability was fixed in DPDK.

Some downstream stakeholders were warned in advance

in order to coordinate the release of fixes

and reduce the vulnerability window.

 

In DPDK Vhost communication, we didn't test if msg->payload.inflight.num_queues is out of bounds in function ‘vhost_user_set_inflight_fd()’, and could cause the program to write OOB.

 

Commits: 6442c329b9d2 on the main branch

 

CVE: CVE-2021-3839

Bugzilla: https://bugs.dpdk.org/show_bug.cgi?id=657

Severity: 5.2 (Medium)

CVSS scores: 3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L