Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1059

21
FAUCET Score

CVE-2018-1059 describes a vulnerability in the DPDK vhost-user interface, affecting all versions prior to 18.02.1, including products from Canonical and Red Hat. The flaw stems from a lack of validation for guest physical memory mappings during address translations, allowing a malicious guest to potentially expose the vhost-user backend process memory. Rated Medium severity with a CVSS score of 6.1 (AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N), this vulnerability requires network access and high attack complexity but could lead to a complete compromise of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
17.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:a:redhat:enterprise_linux_fast_datapath:7.0:*:*:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
4.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.88%
Probability of exploitation in next 30 days
EPSS Percentile
55.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0088 is in the 95th percentile among its peer group of 1,749 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 7Fixed in: openvswitch-0:2.9.0-19.el7fdp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 ExtrasFixed in: dpdk-0:17.11-11.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 10.0 (Newton)Fixed in: openstack-selinux-0:0.8.14-5.el7ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 10.0 (Newton)Fixed in: openvswitch-0:2.9.0-19.el7fdp.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 12.0 (Pike)Fixed in: openvswitch-0:2.9.0-19.el7fdp.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUSFixed in: openvswitch-0:2.9.0-19.el7fdp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.2Fixed in: openvswitch-0:2.9.0-19.el7fdp
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dpdk
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: dpdk
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: openvswitch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 3Fixed in: openvswitch
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: openvswitch-dpdk
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 11 (Ocata)Fixed in: dpdk
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 11 (Ocata)Fixed in: openvswitch
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: openvswitch-dpdk
redhatend of lifevia redhat_api
Product: Fast Datapath for RHEL 7Fixed in: dpdk
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)Fixed in: openvswitch-dpdk

Vendor Advisories (1)

redhatCVE-2018-1059Moderate

dpdk: Information exposure in unchecked guest physical to host virtual address translations

Apr 23, 2018

References

access.redhat.com / errata/RHSA-2018:1267
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2038
access.redhat.com / errata/RHSA-2018:2102
access.redhat.com / errata/RHSA-2018:2524
access.redhat.com / security/cve/cve-2018-1059
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
usn.ubuntu.com / 3642-1
Third Party Advisory
usn.ubuntu.com / 3642-2
Third Party Advisory