A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
2019-11-14T17:15:14.757
2024-11-21T04:27:25.607
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dpdk | data_plane_development_kit | < 16.11.10 | Yes |
Application | dpdk | data_plane_development_kit | < 17.11.8 | Yes |
Application | dpdk | data_plane_development_kit | < 18.11.4 | Yes |
Application | dpdk | data_plane_development_kit | < 19.08.1 | Yes |
Application | redhat | enterprise_linux_fast_datapath | 7.0 | Yes |
Application | redhat | enterprise_linux_fast_datapath | 8.0 | Yes |
Application | redhat | openstack | 10 | Yes |
Application | redhat | virtualization_eus | 4.2 | Yes |
Operating System | fedoraproject | fedora | 31 | Yes |