VulnerabilityModified
CVE-2018-1059
This may lead to a malicious guest exposing vhost-user backend process memory.
MEDIUM 6.1EPSS 0.86%
Does this matter?
Lower severity and a low EPSS score (0.86%). Track it; it rarely justifies an emergency change on its own.
Description
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.86% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- canonical/ubuntu linux · redhat/ceph storage · redhat/enterprise linux fast datapath · redhat/openshift · redhat/openstack · redhat/virtualization · redhat/virtualization manager · redhat/enterprise linux · dpdk/data plane development kit
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2038
- https://access.redhat.com/errata/RHSA-2018:2102
- https://access.redhat.com/errata/RHSA-2018:2524
- https://access.redhat.com/security/cve/cve-2018-1059Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1544298Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/3642-1/Third Party Advisory
- https://usn.ubuntu.com/3642-2/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2038
- https://access.redhat.com/errata/RHSA-2018:2102
- https://access.redhat.com/errata/RHSA-2018:2524
- https://access.redhat.com/security/cve/cve-2018-1059Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1544298Issue Tracking, Third Party Advisory
- https://usn.ubuntu.com/3642-1/Third Party Advisory
- https://usn.ubuntu.com/3642-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.