Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10726

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

Отчет

The versions of DPDK as shipped with Red Hat Enterprise Linux 7 were not affected by this flaw, as they did not include support for the inflight share memory feature, which was introduced in a later version of the package. This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for DPDK.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.11Not affected
Fast Datapath for RHEL 7openvswitch2.12Not affected
Fast Datapath for RHEL 7openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.11Not affected
Fast Datapath for RHEL 8openvswitch2.12Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 7dpdkNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1828898dpdk: librte_vhost VHOST_USER_GET_INFLIGHT_FD message flooding to result in a DoS

EPSS

Процентиль: 30%
0.00112
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6
ubuntu
больше 5 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
nvd
больше 5 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
debian
больше 5 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A maliciou ...

CVSS3: 4.4
github
больше 3 лет назад

A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.

CVSS3: 6
fstec
больше 5 лет назад

Уязвимость модуля vhost-user набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.00112
Низкий

4.4 Medium

CVSS3