Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.6)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+431/8/202217/6/2026
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
ModificadaAlta (7.5)2.0%—OpenvswitchRedhat Enterprise Linux Fast DatapathCanonical Ubuntu LinuxFedoraproject Fedora23/8/202217/6/2026
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
ModificadaAlta (7.5)1.6%—Dpdk Data Plane Development KITFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Fast Datapath23/8/202217/6/2026
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
ModificadaAlta (7.5)2.8%—Dpdk Data Plane Development KITRedhat Enterprise Linux Fast DatapathRedhat OpenstackRedhat Virtualization EUS+114/11/201917/6/2026
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This…
ModificadaMedia (6.1)0.85%—Canonical Ubuntu LinuxRedhat Ceph StorageRedhat Enterprise Linux Fast DatapathRedhat Openshift+524/4/201817/6/2026
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are…