Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1430-1

Опубликовано: 26 мая 2020
Источник: suse-cvrf

Описание

Security update for dpdk

This update for dpdk to 17.11.7 fixes the following issues:

Security issues fixed:

  • CVE-2020-10722: Fixed an integer overflow in vhost_user_set_log_base() (bsc#1171477 bsc#1171930).
  • CVE-2020-10723: Fixed an integer truncation in vhost_user_check_and_alloc_queue_pair() (bsc#1171477).

Список пакетов

SUSE Linux Enterprise Server 12 SP4
dpdk-17.11.7-5.6.2
dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
dpdk-thunderx-17.11.7-5.6.2
dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
dpdk-tools-17.11.7-5.6.2
libdpdk-17_11-17.11.7-5.6.2
SUSE Linux Enterprise Server for SAP Applications 12 SP4
dpdk-17.11.7-5.6.2
dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
dpdk-thunderx-17.11.7-5.6.2
dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
dpdk-tools-17.11.7-5.6.2
libdpdk-17_11-17.11.7-5.6.2
SUSE Linux Enterprise Software Development Kit 12 SP4
dpdk-devel-17.11.7-5.6.2
dpdk-thunderx-devel-17.11.7-5.6.2

Описание

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:dpdk-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2

Ссылки

Описание

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:dpdk-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2

Ссылки

Описание

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4:dpdk-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-kmp-default-17.11.7_k4.12.14_95.51-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-17.11.7-5.6.2
SUSE Linux Enterprise Server 12 SP4:dpdk-thunderx-kmp-default-17.11.7_k4.12.14_95.51-5.6.2

Ссылки
Уязвимость SUSE-SU-2020:1430-1