CVE-2019-9547

In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains.
Configurations

Configuration 1 (hide)

cpe:2.3:a:spdk:storage_performance_development_kit:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:51

Type Values Removed Values Added
References () https://github.com/spdk/spdk/commit/eca42c66092b9031711afe215fbc1891ee55f143 - Third Party Advisory () https://github.com/spdk/spdk/commit/eca42c66092b9031711afe215fbc1891ee55f143 - Third Party Advisory
References () https://github.com/spdk/spdk/releases/tag/v19.01 - Third Party Advisory () https://github.com/spdk/spdk/releases/tag/v19.01 - Third Party Advisory

Information

Published : 2019-03-01 22:29

Updated : 2024-11-21 04:51


NVD link : CVE-2019-9547

Mitre link : CVE-2019-9547

CVE.ORG link : CVE-2019-9547


JSON object : View

Products Affected

spdk

  • storage_performance_development_kit
CWE
CWE-834

Excessive Iteration