Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10726

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 4.4

Описание

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

Отчет

The versions of DPDK as shipped with Red Hat Enterprise Linux 7 were not affected by this flaw, as they did not include support for the inflight share memory feature, which was introduced in a later version of the package. This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for DPDK.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.11Not affected
Fast Datapath for RHEL 7openvswitch2.12Not affected
Fast Datapath for RHEL 7openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.11Not affected
Fast Datapath for RHEL 8openvswitch2.12Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 7dpdkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1828898dpdk: librte_vhost VHOST_USER_GET_INFLIGHT_FD message flooding to result in a DoS

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
около 6 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
nvd
около 6 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
debian
около 6 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A maliciou ...

CVSS3: 4.4
github
около 4 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
fstec
около 6 лет назад

Уязвимость модуля vhost-user набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая нарушителю вызвать отказ в обслуживании

4.4 Medium

CVSS3