Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Storage_performance_development_kit
(Spdk)Repositories | https://github.com/spdk/spdk |
#Vulnerabilities | 3 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-03-13 | CVE-2021-28361 | An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference. | Storage_performance_development_kit | 7.5 | ||
2019-03-01 | CVE-2019-9547 | In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains. | Storage_performance_development_kit | 5.3 | ||
2019-08-12 | CVE-2019-14940 | In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input. | Storage_performance_development_kit | 6.5 |