CVE-2026-86564: Red Hat Fast Datapath For Rhel 10

Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

Affected products

  • Red Hat Fast Datapath For Rhel 10
  • Red Hat Fast Datapath For Rhel 8
  • Red Hat Fast Datapath For Rhel 9
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Openshift Container Platform 4

Published 2026-09-08. Last modified 2026-09-09.