Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14818

Опубликовано: 12 нояб. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

A flaw was found in dpdk where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

Отчет

The dpdk package within Red Hat OpenStack Platform 10 has been superseded by the version included with RHEL Extras, fixes for dpdk will be consumed from here.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitch2.10Will not fix
Fast Datapath for RHEL 8openvswitchNot affected
Fast Datapath for RHEL 8openvswitch2.10Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephAffected
Red Hat OpenStack Platform 10 (Newton)dpdkNot affected
Red Hat OpenStack Platform 10 (Newton)openvswitchOut of support scope
Red Hat OpenStack Platform 14 (Rocky)openvswitchOut of support scope
Fast Datapath for Red Hat Enterprise Linux 7openvswitchFixedRHSA-2020:016521.01.2020
Fast Datapath for Red Hat Enterprise Linux 7openvswitch2.11FixedRHSA-2020:016621.01.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=1737327dpdk: possible memory leak leads to denial of service

EPSS

Процентиль: 78%
0.01168
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

CVSS3: 7.5
nvd
около 6 лет назад

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

CVSS3: 7.5
debian
около 6 лет назад

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x bef ...

suse-cvrf
почти 6 лет назад

Security update for dpdk

suse-cvrf
почти 6 лет назад

Security update for dpdk

EPSS

Процентиль: 78%
0.01168
Низкий

7.5 High

CVSS3