CVE-2018-1059

Severity
6.1MEDIUM
EPSS
0.2%
top 59.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 13

Description

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.

CVSS vector

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:NExploitability: 1.6 | Impact: 4.0

Affected Packages9 packages

Debiandpdk< 17.11.2-1+3
CVEListV5red_hat,_inc./dpdkbefore 18.02.1
NVDredhat/virtualization4.0, 4.1+1

Also affects: Ubuntu Linux 17.10, 18.04, Enterprise Linux 7.0

🔴Vulnerability Details

3
GHSA
GHSA-ww8j-hjq3-7m8r: The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Phys2022-05-13
CVEList
CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Phys2018-04-24
OSV
CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Phys2018-04-24

📋Vendor Advisories

4
Ubuntu
DPDK vulnerability2018-05-16
Ubuntu
DPDK vulnerability2018-05-09
Red Hat
dpdk: Information exposure in unchecked guest physical to host virtual address translations2018-04-23
Debian
CVE-2018-1059: dpdk - The DPDK vhost-user interface does not check to verify that all the requested gu...2018

💬Community

5
Bugzilla
CVE-2018-1059 dpdk: Information exposure in unchecked guest physical to host virtual address translations [fedora-all]2018-04-24
Bugzilla
CVE-2018-1059 dpdk: Information exposure in unchecked guest physical to host virtual address translations [fedora-all]2018-04-24
Bugzilla
CVE-2018-1059 dpdk: Information exposure in unchecked guest physical to host virtual address translations [fedora-all]2018-04-23
Bugzilla
CVE-2018-1059 dpdk: Information exposure in unchecked guest physical to host virtual address translations2018-02-12
Bugzilla
CVE-2018-6616 openjpeg2: Excessive iteration in openjp2/t1.c:opj_t1_encode_cblks can allow for denial of service via crafted BMP file2018-02-06