CVE-2026-86564
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
- Published Sep 8, 2026
- CVSS 3.3 low
- 0.1% chance of exploitation in the next 30 days (EPSS)