Loading HuntDB...

GHSA-6q37-hh76-6rv4

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers config read helpers do not initialize the memory indirectly passed to vduse_vdpa_get_config() returning uninitialized memory from the stack. This could cause undefined behavior or data leaks in Virtio drivers.

Related CVEs

Key Information

GHSA ID
GHSA-6q37-hh76-6rv4
Published
September 2, 2022 12:01 AM
Last Modified
September 8, 2022 12:00 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.