vcswatch reports that
this package has been uploaded into the archive but the debian/changelog in the
VCS is still UNRELEASED. You should consider pushing the missing commits
or updating the VCS.
https://salsa.debian.org/api/v4/projects/debian%2Fdpdk API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
CVE-2026-86564:
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
CVE-2026-86564:
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
1 issue left for the package maintainer to handle:
CVE-2026-86564:
(needs triaging)
A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it.
You can probably find supplementary information in the
debian-release
archives or in the corresponding
release.debian.org
bug.