Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.41% | — | OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+1 | 6/10/2023 | 17/6/2026 | A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses. | |
| Modificada | Media (5.3) | 0.99% | — | OVN Open Virtual NetworkRedhat Openshift Container PlatformRedhat Fast Datapath | 4/10/2023 | 17/6/2026 | A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured. | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Alta (8.6) | 2.2% | — | Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+4 | 31/8/2022 | 17/6/2026 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | |
| Modificada | Alta (7.5) | 2.0% | — | OpenvswitchRedhat Enterprise Linux Fast DatapathCanonical Ubuntu LinuxFedoraproject Fedora | 23/8/2022 | 17/6/2026 | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments. | |
| Modificada | Alta (7.5) | 1.6% | — | Dpdk Data Plane Development KITFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Fast Datapath | 23/8/2022 | 17/6/2026 | A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability. | |
| Modificada | Alta (7.5) | 2.8% | — | Dpdk Data Plane Development KITRedhat Enterprise Linux Fast DatapathRedhat OpenstackRedhat Virtualization EUS+1 | 14/11/2019 | 17/6/2026 | A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This… | |
| Modificada | Media (6.1) | 0.85% | — | Canonical Ubuntu LinuxRedhat Ceph StorageRedhat Enterprise Linux Fast DatapathRedhat Openshift+5 | 24/4/2018 | 17/6/2026 | The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are… |