A vulnerability was found in Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input. Reference: https://github.com/spdk/spdk/releases/tag/v19.07
Statement: This issue did not affect the version of Ceph as shipped with Red Hat Ceph Storage 3 and 4 as they did not include the support for spdk.