https://seclists.org/oss-sec/2024/q4/156: CVE-2024-11614: DPDK Vhost Rx checksum vulnerability
Published Dec 17, 2024
·Updated
Affected Software
1 affected component
DPDK DPDK>=21.11<=24.11
CVE-2024-11614 has been classified as a high-severity vulnerability due to its potential to crash the vhost-user side.
To mitigate CVE-2024-11614, update to the latest version of DPDK that includes the security patch released on December 17, 2024.
CVE-2024-11614 affects the DPDK component, specifically impacting the vhost Rx checksum functionality when using a virtio driver.
Any users of DPDK employing vhost-user functionality with vulnerabilities in their guest systems using virtio drivers may be affected by CVE-2024-11614.
As a workaround for CVE-2024-11614, consider disabling the use of untrusted virtio drivers until an update can be applied.