6.1

CVE-2018-1059

The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 17.10
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Redhat ≫ Ceph Storage Version 3.0
Redhat ≫ Openshift Version 3.0 SwEdition enterprise
Redhat ≫ Openstack Version 8
Redhat ≫ Openstack Version 9
Redhat ≫ Openstack Version 10
Redhat ≫ Openstack Version 11
Redhat ≫ Openstack Version 12
Redhat ≫ Virtualization Version 4.0
Redhat ≫ Virtualization Version 4.1
Redhat ≫ Virtualization Manager Version 4.1
Redhat ≫ Enterprise Linux Version 7.0
Dpdk ≫ Data Plane Development Kit Version < 18.02.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.88% 0.543
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 1.6 4
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
NIST 2.9 5.5 2.9
AV:A/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://access.redhat.com/errata/RHSA-2018:1267
Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2038
https://access.redhat.com/errata/RHSA-2018:2102
https://access.redhat.com/errata/RHSA-2018:2524
https://access.redhat.com/security/cve/cve-2018-1059
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1544298
Third Party Advisory
Issue Tracking
https://usn.ubuntu.com/3642-1/
Third Party Advisory
https://usn.ubuntu.com/3642-2/
Third Party Advisory