Vulnerability Description
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 17.10 |
| Redhat | Ceph Storage | 3.0 |
| Redhat | Enterprise Linux Fast Datapath | 7.0 |
| Redhat | Openshift | 3.0 |
| Redhat | Openstack | 8 |
| Redhat | Virtualization | 4.0 |
| Redhat | Virtualization Manager | 4.1 |
| Redhat | Enterprise Linux | 7.0 |
| Dpdk | Data Plane Development Kit | < 18.02.1 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2038
- https://access.redhat.com/errata/RHSA-2018:2102
- https://access.redhat.com/errata/RHSA-2018:2524
- https://access.redhat.com/security/cve/cve-2018-1059Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1544298Issue TrackingThird Party Advisory
- https://usn.ubuntu.com/3642-1/Third Party Advisory
- https://usn.ubuntu.com/3642-2/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1267Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2038
- https://access.redhat.com/errata/RHSA-2018:2102
- https://access.redhat.com/errata/RHSA-2018:2524
- https://access.redhat.com/security/cve/cve-2018-1059Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1544298Issue TrackingThird Party Advisory
- https://usn.ubuntu.com/3642-1/Third Party Advisory
FAQ
What is CVE-2018-1059?
CVE-2018-1059 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translati...
How severe is CVE-2018-1059?
CVE-2018-1059 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1059?
Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Redhat Ceph Storage, Redhat Enterprise Linux Fast Datapath, Redhat Openshift, Redhat Openstack.