CHANGELOG: add note on vhost vulnerability

Signed-off-by: Jim Harris <>
Change-Id: Id47256ecfc5d774e7d8054423cda32a90f0c4f76

Chandler-Test-Pool: SPDK Automated Test System <>
Tested-by: SPDK CI Jenkins <>
Reviewed-by: Darek Stojaczyk <>
Reviewed-by: Tomasz Zawadzki <>
jimharris authored and darsto committed Feb 1, 2019
1 parent ce75af2 commit eca42c66092b9031711afe215fbc1891ee55f143
### vhost

A security vulnerability has been identified and fixed in the SPDK vhost target. A malicious
vhost client (i.e. virtual machine) could carefully construct a circular descriptor chain which
would result in a partial denial of service in the SPDK vhost target. These types of descriptor
chains are now properly detected by the vhost target. All SPDK vhost users serving untrusted
vhost clients are strongly recommended to upgrade. (Reported by Dima Stepanov and Evgeny

Vhost SCSI and Vhost Block devices can now accept multiple connections on the same socket file.
Each connection (internally called a vhost session) will have access to the same storage, but
will use different virtqueues, different features and possibly different memory.

