Wind River Support Network

HomeDefectsLIN1021-3493
Fixed

LIN1021-3493 : Security Advisory - dpdk - CVE-2021-3839

Created: May 5, 2022    Updated: Mar 23, 2025
Resolved Date: Dec 30, 2024
Found In Version: 10.21.20.1
Fix Version: 10.21.20.25
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate 'msg->payload.inflight.num_queues', possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.

CVEs


Live chat
Online