PT-2019-5188 · Intel+5 · Dpdk+5
Publicado
2019-11-12
·
Atualizado
2024-06-15
·
CVE-2019-14818
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
dpdk versions 16.x.x through 16.11.9
dpdk versions 17.x.x through 17.11.7
dpdk versions 18.x.x through 18.11.3
dpdk versions 19.x.x through 19.08.0
Description
The issue is related to an uncontrolled resource consumption in the dpdk library and driver set, which can be exploited by a remote attacker to cause a denial of service by sending specially crafted
VRING SET NUM messages. This can result in a memory leak, including file descriptors, when a malicious master or a container with access to the vhost user socket sends these messages.Recommendations
For dpdk versions 16.x.x through 16.11.9, update to version 16.11.10 or later.
For dpdk versions 17.x.x through 17.11.7, update to version 17.11.8 or later.
For dpdk versions 18.x.x through 18.11.3, update to version 18.11.4 or later.
For dpdk versions 19.x.x through 19.08.0, update to version 19.08.1 or later.
Correção
DoS
Memory Leak
Resource Exhaustion
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Dpdk