PT-2018-4341 · Linux Foundation+3 · Dpdk+4

Igor Smolyar

·

Published

2018-01-23

·

Updated

2018-06-07

·

CVE-2015-1142857

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel ixgbe driver versions before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1 Linux Kernel i40e/i40evf driver versions before e7358f54a3954df16d4f87e3cad35063f1c17de5 DPDK versions before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0 Multiple vendor NIC firmware (affected versions not specified)
Description The issue allows VF's assigned to guests on multiple SR-IOV cards to send ethernet flow control pause frames via the PF. This affects various drivers and firmware.
Recommendations For Linux kernel ixgbe driver versions before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, update to a version that includes commit f079fa005aae08ee0e1bc32699874ff4f02e11c1 or later. For Linux Kernel i40e/i40evf driver versions before e7358f54a3954df16d4f87e3cad35063f1c17de5, update to a version that includes commit e7358f54a3954df16d4f87e3cad35063f1c17de5 or later. For DPDK versions before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, update to a version that includes commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0 or later. For Multiple vendor NIC firmware, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1142857
SUSE-SU-2018:0437-1
SUSE-SU-2018:0525-1
SUSE-SU-2018:0555-1
SUSE-SU-2018:0671-1
SUSE-SU-2018:0674-1
SUSE-SU-2018:0841-1
SUSE-SU-2018:1567-1
SUSE-SU-2018:1570-1
SUSE-SU-2018_0671-1
SUSE-SU-2018_0674-1

Affected Products

Dpdk
Linux Kernel
Suse
I40E/I40Evf Driver
Ixgbe Driver