CVE-2019-9547: Spdk Storage Performance Development Kit
Medium severity, CVSS 5.3. EPSS: 1.5% chance of exploitation in the next 30 days.
In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains.
Affected products
- Spdk Storage Performance Development Kit: before 19.01 (fixed in 19.01)
Published 2019-03-01. Last modified 2026-06-17.