Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.851775
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for dpdk-thunderxdpdk (openSUSE-SU-2018:1560-1)
Summary:The remote host is missing an update for the 'dpdk-thunderxdpdk'; package(s) announced via the referenced advisory.
Description:Summary:
The remote host is missing an update for the 'dpdk-thunderxdpdk'
package(s) announced via the referenced advisory.

Vulnerability Insight:
This update fixes the following issues:

- CVE-2018-1059: The DPDK vhost-user interface did not check to verify
that all the requested guest physical range was mapped and contiguous
when performing Guest Physical Addresses to Host Virtual Addresses
translations. This may have lead to a malicious guest exposing
vhost-user backend process memory (bsc#1089638).

This update was imported from the SUSE:SLE-12-SP3:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended
installation methods
like YaST online_update or 'zypper patch'.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-558=1

Affected Software/OS:
dpdk-thunderxdpdk on openSUSE Leap 42.3

Solution:
Please install the updated package(s).

CVSS Score:
2.9

CVSS Vector:
AV:A/AC:M/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-1059
https://access.redhat.com/security/cve/cve-2018-1059
RedHat Security Advisories: RHSA-2018:1267
https://access.redhat.com/errata/RHSA-2018:1267
RedHat Security Advisories: RHSA-2018:2038
https://access.redhat.com/errata/RHSA-2018:2038
RedHat Security Advisories: RHSA-2018:2102
https://access.redhat.com/errata/RHSA-2018:2102
RedHat Security Advisories: RHSA-2018:2524
https://access.redhat.com/errata/RHSA-2018:2524
https://usn.ubuntu.com/3642-1/
https://usn.ubuntu.com/3642-2/
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.