DPDK announcements
 help / color / mirror / Atom feed
* CVE-2021-3839 Release Notice
@ 2022-05-05  1:42 Jiang, Cheng1
  0 siblings, 0 replies; only message in thread
From: Jiang, Cheng1 @ 2022-05-05  1:42 UTC (permalink / raw)
  To: announce

[-- Attachment #1: Type: text/plain, Size: 557 bytes --]

A vulnerability was fixed in DPDK.
Some downstream stakeholders were warned in advance
in order to coordinate the release of fixes
and reduce the vulnerability window.

In DPDK Vhost communication, we didn't test if msg->payload.inflight.num_queues is out of bounds in function 'vhost_user_set_inflight_fd()', and could cause the program to write OOB.

Commits: 6442c329b9d2 on the main branch

CVE: CVE-2021-3839
Bugzilla: https://bugs.dpdk.org/show_bug.cgi?id=657
Severity: 5.2 (Medium)
CVSS scores: 3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L

[-- Attachment #2: Type: text/html, Size: 2809 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2022-05-09 17:51 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-05-05  1:42 CVE-2021-3839 Release Notice Jiang, Cheng1

DPDK announcements

This inbox may be cloned and mirrored by anyone:

	git clone --mirror http://inbox.dpdk.org/announce/0 announce/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 announce announce/ http://inbox.dpdk.org/announce \
	public-inbox-index announce

Example config snippet for mirrors.
Newsgroup available over NNTP:

AGPL code for this site: git clone https://public-inbox.org/public-inbox.git