Wind River Support Network

HomeDefectsLIN1021-3493
Fixed

LIN1021-3493 : Security Advisory - dpdk - CVE-2021-3839

Created: May 5, 2022    Updated: Dec 30, 2024
Resolved Date: Dec 30, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate 'msg->payload.inflight.num_queues', possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

CVEs


Live chat
Online