CVE-2024-11614
Last modified
CVE-2024-11614 is a vulnerability of currently unknown severity. An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
An out-of-bounds read vulnerability was found in DPDK's Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor's vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-11614?
How severe is CVE-2024-11614?
How do I fix CVE-2024-11614?
Are you affected by CVE-2024-11614?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
