spdk CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

spdk vulnerability overview

Aggregates CVE and security vulnerability intelligence across all spdk-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk memory corruption and vendor risk denial of service and related problems; some flaws may lead to vendor impact application crash, affecting vendor surface production workloads scenarios.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-28361 An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI target with a zero length (but data is expected), the iSCSI target can crash with a NULL pointer dereference. [email protected] 7.5 0.54% 2021-03-13 2024-11-21
CVE-2019-14940 In Storage Performance Development Kit (SPDK) before 19.07, a user of a vhost can cause a crash if the target is sent invalid input. [email protected] 6.5 0.31% 2019-08-12 2024-11-21
CVE-2019-9547 In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could carefully construct a circular descriptor chain that would result in a partial denial of service in the SPDK vhost target, because the vhost target did not properly detect such chains. [email protected] 5.3 0.30% 2019-03-01 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence