SPDK is a specialized storage performance development kit providing user-space libraries and tools for optimized I/O operations, occupying a focused but critical role in high-performance storage and data center infrastructure. The observed weakness classes center on iteration-control issues, NULL-pointer dereferences, and related memory-safety concerns that arise in systems-level storage code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spdk over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28361HIGH An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI tar | Mar 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-14940MEDIUM In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input. | Aug 12, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-9547MEDIUM In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result | Mar 1, 2019 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spdk.
Media articles that mention a CVE ID that affects a product developed by Spdk — matched by CVE ID, not by vendor name.