CVE Vulnerabilities

CVE-2022-0669

Published: Aug 29, 2022 | Modified: Sep 01, 2022
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

Affected Software

Name Vendor Start Version End Version
Data_plane_development_kit Dpdk 20.02 (including) 22.03 (excluding)
Data_plane_development_kit Dpdk 19.11 (including) 19.11 (including)
Data_plane_development_kit Dpdk 19.11-rc1 (including) 19.11-rc1 (including)
Data_plane_development_kit Dpdk 19.11-rc2 (including) 19.11-rc2 (including)
Data_plane_development_kit Dpdk 19.11-rc3 (including) 19.11-rc3 (including)
Data_plane_development_kit Dpdk 19.11-rc4 (including) 19.11-rc4 (including)
Data_plane_development_kit Dpdk 22.03-rc1 (including) 22.03-rc1 (including)
Data_plane_development_kit Dpdk 22.03-rc2 (including) 22.03-rc2 (including)
Data_plane_development_kit Dpdk 22.03-rc3 (including) 22.03-rc3 (including)

References