CVE-2018-1059: Canonical Ubuntu Linux
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
Affected products
- Canonical Ubuntu Linux: version 17.10 only; version 18.04 only
- Dpdk Data Plane Development Kit: before 18.02.1 (fixed in 18.02.1)
- Red Hat Ceph Storage: version 3.0 only
- Red Hat Enterprise Linux: version 7.0 only
- Red Hat Enterprise Linux Fast Datapath: version 7.0 only
- Red Hat Openshift: version 3.0 only
- Red Hat Openstack: version 8 only; version 9 only; version 10 only; version 11 only; version 12 only
- Red Hat Virtualization: version 4.0 only; version 4.1 only
- Red Hat Virtualization Manager: version 4.1 only
Published 2018-04-24. Last modified 2026-06-17.