Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2132

Опубликовано: 29 авг. 2022
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

Отчет

In OpenShift Container Platform (OCP) the openvswitch rpm package is consumed from the RHEL Fast Datapath repositories, hence OCP openvswitch components are marked as "Will not fix".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.12Affected
Fast Datapath for RHEL 8openvswitch2.12Affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat OpenShift Container Platform 4openvswitch2.13Will not fix
Red Hat OpenShift Container Platform 4openvswitch2.15Will not fix
Red Hat OpenShift Container Platform 4openvswitch2.16Will not fix
Red Hat OpenStack Platform 13 (Queens)rhosp-openvswitchNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-791->CWE-183->CWE-641->CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2099475dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs

EPSS

Процентиль: 63%
0.00446
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 3 года назад

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

CVSS3: 8.6
nvd
почти 3 года назад

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

CVSS3: 8.6
debian
почти 3 года назад

A permissive list of allowed inputs flaw was found in DPDK. This issue ...

suse-cvrf
больше 1 года назад

Security update for dpdk

suse-cvrf
больше 1 года назад

Security update for dpdk

EPSS

Процентиль: 63%
0.00446
Низкий

8.6 High

CVSS3

Уязвимость CVE-2022-2132