CVE Vulnerabilities

CVE-2022-2132

Incomplete Filtering of Special Elements

Published: Aug 31, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

Weakness

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Affected Software

NameVendorStart VersionEnd Version
Data_plane_development_kitDpdk*19.11 (excluding)
Data_plane_development_kitDpdk20.0 (including)20.11 (excluding)
Data_plane_development_kitDpdk21.0 (including)21.11 (excluding)
Fast Datapath for Red Hat Enterprise Linux 7RedHatopenvswitch2.11-0:2.11.3-96.2.el7fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatopenvswitch2.16-0:2.16.0-89.2.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatopenvswitch2.17-0:2.17.0-37.3.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatopenvswitch2.13-0:2.13.0-193.2.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 8RedHatopenvswitch2.15-0:2.15.0-113.2.el8fdp*
Fast Datapath for Red Hat Enterprise Linux 9RedHatopenvswitch2.17-0:2.17.0-32.3.el9fdp*
Red Hat Enterprise Linux 7 ExtrasRedHatdpdk-0:18.11.8-2.el7_9*
Red Hat Enterprise Linux 8RedHatdpdk-0:21.11-2.el8_7*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatdpdk-0:18.11.2-5.el8_1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatdpdk-0:19.11-6.el8_2*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatdpdk-0:19.11-6.el8_2*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatdpdk-0:19.11-6.el8_2*
Red Hat Enterprise Linux 8.4 Extended Update SupportRedHatdpdk-0:20.11-4.el8_4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatdpdk-0:21.11-2.el8_6*
Red Hat Enterprise Linux 9RedHatdpdk-2:21.11.2-1.el9_1*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatdpdk-2:21.11-2.el9_0*
Red Hat OpenStack Platform 13.0 - ELSRedHatopenvswitch2.11-0:2.11.3-96.2.el7fdp*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatredhat-virtualization-host-0:4.5.2-202209140405_8.6*
DpdkUbuntubionic*
DpdkUbuntudevel*
DpdkUbuntuesm-infra/bionic*
DpdkUbuntuesm-infra/focal*
DpdkUbuntuesm-infra/xenial*
DpdkUbuntufocal*
DpdkUbuntujammy*
DpdkUbuntukinetic*
DpdkUbuntulunar*
DpdkUbuntumantic*
DpdkUbuntunoble*
DpdkUbuntuoracular*
DpdkUbuntuplucky*
DpdkUbuntuquesting*
DpdkUbuntuxenial*

References