https://seclists.org/oss-sec/2024/q4/156: CVE-2024-11614: DPDK Vhost Rx checksum vulnerability
Published Dec 17, 2024
·Updated
Affected Software
1 affected component
DPDK DPDK>=21.11<=24.11
Frequently Asked Questions
1
What is the severity of CVE-2024-11614?
CVE-2024-11614 has been classified as a high-severity vulnerability due to its potential to crash the vhost-user side.
2
How do I fix CVE-2024-11614?
To mitigate CVE-2024-11614, update to the latest version of DPDK that includes the security patch released on December 17, 2024.
3
What does CVE-2024-11614 affect?
CVE-2024-11614 affects the DPDK component, specifically impacting the vhost Rx checksum functionality when using a virtio driver.
4
Who is affected by CVE-2024-11614?
Any users of DPDK employing vhost-user functionality with vulnerabilities in their guest systems using virtio drivers may be affected by CVE-2024-11614.
5
What is the workaround for CVE-2024-11614?
As a workaround for CVE-2024-11614, consider disabling the use of untrusted virtio drivers until an update can be applied.