Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <0cf17b4c-0681-4bb7-b09a-f4e9f3a3ab54@redhat.com>
Date: Tue, 17 Dec 2024 16:02:33 +0100
From: Maxime Coquelin <maxime.coquelin@...hat.com>
To: announce@...k.org, oss-security@...ts.openwall.com
Subject: CVE-2024-11614: DPDK Vhost Rx checksum vulnerability

A vulnerability was fixed in DPDK.

Some downstream stakeholders were warned in advance through
security-prerelease@...k.org in order to coordinate the release
of fixes and reduce the vulnerability window [0].

A malicious guest using a virtio driver can cause the vhost-user side to
crash by sending a packet with a Tx checksum offload request and an
invalid csum_start offset.

Commits per branch:
	main  - 
https://git.dpdk.org/dpdk/commit/?id=4dc4e33ffa108e945fc8a1e2bbc7819791faa61e
	24.11 - 
https://git.dpdk.org/dpdk-stable/commit/?id=fdf13ea6fede07538fbe5e2a46fa6d4b2368fa81
	23.11 - 
https://git.dpdk.org/dpdk-stable/commit/?id=b8e7797c11e5121d738b8c468ee08f3411474d1c
	22.11 - 
https://git.dpdk.org/dpdk-stable/commit/?id=1570aef08bfde179449a9501bd54888a7d5f2cd6
	21.11 - 
https://git.dpdk.org/dpdk-stable/commit/?id=e9c0ad133242c0bcb7801d2590e8bb5f7ac4ebfd

LTS Releases:
	24.11 - https://fast.dpdk.org/rel/dpdk-24.11.1.tar.xz
	23.11 - https://fast.dpdk.org/rel/dpdk-23.11.3.tar.xz
	22.11 - https://fast.dpdk.org/rel/dpdk-22.11.7.tar.xz
	21.11 - https://fast.dpdk.org/rel/dpdk-21.11.9.tar.xz

CVE: CVE-2024-11614
Severity: 7.2
CVSS scores: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:F/RC:C

[0]: https://mails.dpdk.org/listinfo/security-prerelease

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.