{"id":"CVE-2021-3839","details":"A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg-\u003epayload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.","modified":"2026-07-09T01:31:43.189518Z","published":"2022-08-23T16:15:10.087Z","related":["ALSA-2022:8263","SUSE-SU-2022:1892-1","SUSE-SU-2022:2273-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"35"},{"last_affected":"35"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora"},{"cpes":["cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"},{"introduced":"9.0"},{"last_affected":"9.0"}],"source":"CPE_STRING","vendor_product":"redhat:enterprise_linux"},{"vendor_product":"redhat:enterprise_linux_fast_datapath","cpes":["cpe:2.3:a:redhat:enterprise_linux_fast_datapath:7.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:enterprise_linux_fast_datapath:8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"8.0"},{"last_affected":"8.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2021-3839"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2025882"},{"type":"FIX","url":"https://github.com/DPDK/dpdk/commit/6442c329b9d2ded0f44b27d2016aaba8ba5844c5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dpdk/dpdk","events":[{"introduced":"0"},{"fixed":"80c5b4d6355d1dbece8dd1f812d374f3e24086bc"},{"introduced":"2e07139b66a810883871ff20a5f31e4c222e5b40"},{"last_affected":"312b94ef884f0cf4ee42dde36acf23a41172794d"},{"fixed":"6442c329b9d2ded0f44b27d2016aaba8ba5844c5"}],"database_specific":{"cpe":["cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc1:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc2:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"22.03"},{"introduced":"22.03-rc1"},{"last_affected":"22.03-rc1"},{"introduced":"22.03-rc2"},{"last_affected":"22.03-rc2"},{"introduced":"22.03-rc3"},{"last_affected":"22.03-rc3"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["22.03-rc1","22.03-rc2","22.03-rc3","v22.03-rc4","v22.03-rc3","v22.03-rc2","v22.03-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3839.json","vanir_signatures_modified":"2026-07-09T01:31:43Z","vanir_signatures":[{"target":{"file":"lib/vhost/vhost_user.c"},"deprecated":false,"digest":{"line_hashes":["218964855366889817698744017324434491215","153393868971813765081598737286992637585","215130104168108337750727703366659950908","135045007302257789395044528308605937321"],"threshold":0.9},"id":"CVE-2021-3839-07035299","signature_type":"Line","signature_version":"v1","source":"https://github.com/dpdk/dpdk/commit/6442c329b9d2ded0f44b27d2016aaba8ba5844c5"},{"deprecated":false,"digest":{"function_hash":"340127545324019451371334732147163230990","length":789},"id":"CVE-2021-3839-60bcf5ef","signature_type":"Function","signature_version":"v1","source":"https://github.com/dpdk/dpdk/commit/6442c329b9d2ded0f44b27d2016aaba8ba5844c5","target":{"file":"lib/vhost/vhost_user.c","function":"vhost_user_check_and_alloc_queue_pair"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}