A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
2022-08-29T15:15:09.750
2024-11-21T06:39:08.920
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dpdk | data_plane_development_kit | < 22.03 | Yes |
Application | dpdk | data_plane_development_kit | 19.11 | Yes |
Application | dpdk | data_plane_development_kit | 19.11 | Yes |
Application | dpdk | data_plane_development_kit | 19.11 | Yes |
Application | dpdk | data_plane_development_kit | 19.11 | Yes |
Application | dpdk | data_plane_development_kit | 19.11 | Yes |
Application | dpdk | data_plane_development_kit | 22.03 | Yes |
Application | dpdk | data_plane_development_kit | 22.03 | Yes |
Application | dpdk | data_plane_development_kit | 22.03 | Yes |
Application | openvswitch | openvswitch | 2.13.0 | Yes |
Application | openvswitch | openvswitch | 2.15.0 | Yes |
Application | redhat | openshift_container_platform | 4.0 | Yes |