SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1059

This may lead to a malicious guest exposing vhost-user backend process memory.

MEDIUM 6.1EPSS 0.86%

Does this matter?

Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.

Description

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS
0.86% probability · 57th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
canonical/ubuntu linux · redhat/ceph storage · redhat/enterprise linux fast datapath · redhat/openshift · redhat/openstack · redhat/virtualization · redhat/virtualization manager · redhat/enterprise linux · dpdk/data plane development kit
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.