{
  "threat_severity" : "Moderate",
  "public_date" : "2018-04-23T00:00:00Z",
  "bugzilla" : {
    "description" : "dpdk: Information exposure in unchecked guest physical to host virtual address translations",
    "id" : "1544298",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1544298"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.1",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-200",
  "details" : [ "The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.", "The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory." ],
  "statement" : "Red Hat OpenStack Platform versions 7 to 9 provided openvswitch-dpdk as a technical preview for customers, it was provided without support and is not intended on being deployed in production.\nRed Hat Ceph Storage version 3 provides ceph bundled with DPDK as a technical preview for customers. It was provided without support and is not intended on being deployed in production.",
  "acknowledgement" : "This issue was discovered by Maxime Coquelin (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 7",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1267",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath",
    "package" : "openvswitch-0:2.9.0-19.el7fdp"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extras",
    "release_date" : "2018-06-26T00:00:00Z",
    "advisory" : "RHSA-2018:2038",
    "cpe" : "cpe:/a:redhat:rhel_extras_other:7",
    "package" : "dpdk-0:17.11-11.el7"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10.0 (Newton)",
    "release_date" : "2018-06-28T00:00:00Z",
    "advisory" : "RHSA-2018:2102",
    "cpe" : "cpe:/a:redhat:openstack:10::el7",
    "package" : "openstack-selinux-0:0.8.14-5.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10.0 (Newton)",
    "release_date" : "2018-06-28T00:00:00Z",
    "advisory" : "RHSA-2018:2102",
    "cpe" : "cpe:/a:redhat:openstack:10::el7",
    "package" : "openvswitch-0:2.9.0-19.el7fdp.1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 12.0 (Pike)",
    "release_date" : "2018-08-20T00:00:00Z",
    "advisory" : "RHSA-2018:2524",
    "cpe" : "cpe:/a:redhat:openstack:12::el7",
    "package" : "openvswitch-0:2.9.0-19.el7fdp.1"
  }, {
    "product_name" : "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS",
    "release_date" : "2018-04-30T00:00:00Z",
    "advisory" : "RHSA-2018:1267",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "openvswitch-0:2.9.0-19.el7fdp"
  }, {
    "product_name" : "Red Hat Virtualization Engine 4.2",
    "release_date" : "2018-05-15T00:00:00Z",
    "advisory" : "RHEA-2018:1547",
    "cpe" : "cpe:/a:redhat:rhev_manager:4.2",
    "package" : "openvswitch-0:2.9.0-19.el7fdp"
  } ],
  "package_state" : [ {
    "product_name" : "Fast Datapath for RHEL 7",
    "fix_state" : "Will not fix",
    "package_name" : "dpdk",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
  }, {
    "product_name" : "Red Hat Ceph Storage 3",
    "fix_state" : "Not affected",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "dpdk",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "dpdk",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch-dpdk",
    "cpe" : "cpe:/a:redhat:openstack:7"
  }, {
    "product_name" : "Red Hat OpenShift Enterprise 3",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/a:redhat:openshift:3"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Affected",
    "package_name" : "dpdk",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat OpenStack Platform 11 (Ocata)",
    "fix_state" : "Will not fix",
    "package_name" : "dpdk",
    "cpe" : "cpe:/a:redhat:openstack:11"
  }, {
    "product_name" : "Red Hat OpenStack Platform 11 (Ocata)",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/a:redhat:openstack:11"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Affected",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/a:redhat:openstack:13"
  }, {
    "product_name" : "Red Hat OpenStack Platform 8 (Liberty)",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch-dpdk",
    "cpe" : "cpe:/a:redhat:openstack:8"
  }, {
    "product_name" : "Red Hat OpenStack Platform 9 (Mitaka)",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch-dpdk",
    "cpe" : "cpe:/a:redhat:openstack:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-1059\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-1059\nhttps://access.redhat.com/security/cve/CVE-2018-1059" ],
  "name" : "CVE-2018-1059",
  "csaw" : false
}