{"id":"CVE-2026-86564","title":"A flaw was found in DPDK lib/vhost","summary":"A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-125"],"vendor":"Red Hat","product":"openvswitch3.5","affected":["openvswitch3.5 (all versions)","openvswitch3.6 (all versions)","openvswitch2.11 (all versions)","openvswitch2.12 (all versions)","openvswitch2.13 (all versions)","openvswitch2.15 (all versions)","openvswitch2.16 (all versions)","openvswitch2.17 (all versions)","openvswitch3.1 (all versions)","openvswitch2.17 (all versions)","openvswitch3.0 (all versions)","openvswitch3.1 (all versions)","openvswitch3.2 (all versions)","openvswitch3.3 (all versions)","openvswitch3.4 (all versions)","openvswitch3.5 (all versions)","openvswitch3.6 (all versions)","dpdk (all versions)","dpdk (all versions)","dpdk (all versions)","openvswitch2.17 (all versions)","openvswitch3.0 (all versions)","openvswitch3.1 (all versions)"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T15:44:42.450","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86564","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-86564","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529682","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86564.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86564"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86564"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-09T13:14:12.366766Z"},"ingestedAt":"2026-09-08T23:13:54.646Z","epss":0.00141,"epssPercentile":0.02784,"slug":"CVE-2026-86564","body":"## Overview\n\nA flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Fast Datapath for RHEL 10, Fast Datapath for RHEL 8, Fast Datapath for RHEL 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · no fix planned: Fast Datapath for RHEL 10, Fast Datapath for RHEL 8, Fast Datapath for RHEL 9, Red Hat Enterprise Linux 10, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-86564.json)","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}