Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2022:8263

Опубликовано: 15 нояб. 2022
Источник: rocky
Оценка: Important

Описание

Important: dpdk security and bug fix update

The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space.

Security Fix(es):

  • dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132)

  • DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash (CVE-2021-3839)

  • dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service (CVE-2022-28199)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 9.1 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
dpdkx86_641.el9_1dpdk-21.11.2-1.el9_1.x86_64.rpm
dpdk-develx86_641.el9_1dpdk-devel-21.11.2-1.el9_1.x86_64.rpm
dpdk-docnoarch1.el9_1dpdk-doc-21.11.2-1.el9_1.noarch.rpm
dpdk-toolsx86_641.el9_1dpdk-tools-21.11.2-1.el9_1.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 2 лет назад

ELSA-2022-8263: dpdk security and bug fix update (IMPORTANT)

suse-cvrf
почти 3 года назад

Security update for dpdk

suse-cvrf
почти 3 года назад

Security update for dpdk

suse-cvrf
почти 3 года назад

Security update for dpdk

CVSS3: 7.5
ubuntu
почти 3 года назад

A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.