CVE-2026-86564

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

  • Published Sep 8, 2026
  • CVSS 3.3 low
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-86564 at the National Vulnerability Database