<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2025-0088</id>
    <title>An update for dpdk is now available for HCE 2.0</title>
    <severity>Important</severity>
    <release>HCE 2.0</release>
    <issued date="2025-02-27 13:08:34"/>
    <updated date="2025-02-27 13:08:34"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-11614" id="CVE-2024-11614" title="CVE-2024-11614 Base Score: 7.4 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

An out-of-bounds read vulnerability was found in DPDK_x27;s Vhost library checksum offload feature. This issue enables an untrusted or compromised guest to crash the hypervisor_x27;s vSwitch by forging Virtio descriptors to cause out-of-bounds reads. This flaw allows an attacker with a malicious VM using a virtio driver to cause the vhost-user side to crash by sending a packet with a Tx checksum offload request and an invalid csum_start offset. (CVE-2024-11614)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="dpdk">
        <name>HCE 2.0</name>
        <package arch="aarch64" name="dpdk" version="21.11" release="9.r15.hce2">
          <filename>dpdk-21.11-9.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="dpdk-devel" version="21.11" release="9.r15.hce2">
          <filename>dpdk-devel-21.11-9.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="dpdk-tools" version="21.11" release="9.r15.hce2">
          <filename>dpdk-tools-21.11-9.r15.hce2.aarch64.rpm</filename>
        </package>
        <package arch="x86_64" name="dpdk" version="21.11" release="9.r15.hce2">
          <filename>dpdk-21.11-9.r15.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="dpdk-devel" version="21.11" release="9.r15.hce2">
          <filename>dpdk-devel-21.11-9.r15.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="dpdk-tools" version="21.11" release="9.r15.hce2">
          <filename>dpdk-tools-21.11-9.r15.hce2.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
