OESA-2025-1003

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2025-1003
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2025-1003.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2025-1003
Upstream
Published
2025-01-03T12:54:23Z
Modified
2025-09-03T06:19:54.052256Z
Summary
dpdk security update
Details

The Data Plane Development Kit is a set of libraries and drivers for fast packet processing in the user space.

Security Fix(es):

An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.(CVE-2024-11614)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:24.03-LTS / dpdk

Package

Name
dpdk
Purl
pkg:rpm/openEuler/dpdk&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
23.11-26.oe2403

Ecosystem specific

{
    "src": [
        "dpdk-23.11-26.oe2403.src.rpm"
    ],
    "x86_64": [
        "dpdk-23.11-26.oe2403.x86_64.rpm",
        "dpdk-debuginfo-23.11-26.oe2403.x86_64.rpm",
        "dpdk-debugsource-23.11-26.oe2403.x86_64.rpm",
        "dpdk-devel-23.11-26.oe2403.x86_64.rpm",
        "dpdk-tools-23.11-26.oe2403.x86_64.rpm"
    ],
    "aarch64": [
        "dpdk-23.11-26.oe2403.aarch64.rpm",
        "dpdk-debuginfo-23.11-26.oe2403.aarch64.rpm",
        "dpdk-debugsource-23.11-26.oe2403.aarch64.rpm",
        "dpdk-devel-23.11-26.oe2403.aarch64.rpm",
        "dpdk-tools-23.11-26.oe2403.aarch64.rpm"
    ]
}