Bug 2529887 - CVE-2026-86564 grout: dpdk: Missing length validation before reading command_data in virtio-net control queue handler [fedora-all]
Summary: CVE-2026-86564 grout: dpdk: Missing length validation before reading command_...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: grout
Version: rawhide
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
Assignee: Robin Jarry
QA Contact:
URL:
Whiteboard: {"flaws": ["3d5c4d27-8640-4090-acf4-b...
Depends On:
Blocks: CVE-2026-86564
TreeView+ depends on / blocked
 
Reported: 2026-09-08 15:35 UTC by Ganesh
Modified: 2026-09-08 15:35 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-08 15:35:20 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in DPDK lib/vhost. The virtio-net control-queue handler reads command_data without validating that the copied request is long enough. This out-of-bounds read can cause a host process crash under hardened allocators or sanitizers.


Note You need to log in before you can comment on or make changes to this bug.