OESA-2024-2599

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-2599
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2024-2599.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2024-2599
Upstream
Published
2024-12-27T12:33:56Z
Modified
2025-09-03T06:19:53.872458Z
Summary
dpdk security update
Details

The Data Plane Development Kit is a set of libraries and drivers for fast packet processing in the user space.

Security Fix(es):

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.(CVE-2024-11614)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:22.03-LTS-SP4 / dpdk

Package

Name
dpdk
Purl
pkg:rpm/openEuler/dpdk&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
21.11-81.oe2203sp4

Ecosystem specific

{
    "x86_64": [
        "dpdk-21.11-81.oe2203sp4.x86_64.rpm",
        "dpdk-debuginfo-21.11-81.oe2203sp4.x86_64.rpm",
        "dpdk-debugsource-21.11-81.oe2203sp4.x86_64.rpm",
        "dpdk-devel-21.11-81.oe2203sp4.x86_64.rpm",
        "dpdk-tools-21.11-81.oe2203sp4.x86_64.rpm"
    ],
    "aarch64": [
        "dpdk-21.11-81.oe2203sp4.aarch64.rpm",
        "dpdk-debuginfo-21.11-81.oe2203sp4.aarch64.rpm",
        "dpdk-debugsource-21.11-81.oe2203sp4.aarch64.rpm",
        "dpdk-devel-21.11-81.oe2203sp4.aarch64.rpm",
        "dpdk-tools-21.11-81.oe2203sp4.aarch64.rpm"
    ],
    "noarch": [
        "dpdk-doc-21.11-81.oe2203sp4.noarch.rpm"
    ],
    "src": [
        "dpdk-21.11-81.oe2203sp4.src.rpm"
    ]
}