PT-2019-5188 · Intel+5 · Dpdk+5

Published

2019-11-12

·

Updated

2024-06-15

·

CVE-2019-14818

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dpdk versions 16.x.x through 16.11.9 dpdk versions 17.x.x through 17.11.7 dpdk versions 18.x.x through 18.11.3 dpdk versions 19.x.x through 19.08.0
Description The issue is related to an uncontrolled resource consumption in the dpdk library and driver set, which can be exploited by a remote attacker to cause a denial of service by sending specially crafted VRING SET NUM messages. This can result in a memory leak, including file descriptors, when a malicious master or a container with access to the vhost user socket sends these messages.
Recommendations For dpdk versions 16.x.x through 16.11.9, update to version 16.11.10 or later. For dpdk versions 17.x.x through 17.11.7, update to version 17.11.8 or later. For dpdk versions 18.x.x through 18.11.3, update to version 18.11.4 or later. For dpdk versions 19.x.x through 19.08.0, update to version 19.08.1 or later.

Fix

DoS

Memory Leak

Resource Exhaustion

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3403
ALT-PU-2020-1049
BDU:2020-01861
CESA-2020_1735
CVE-2019-14818
DSA-4567-1
OPENSUSE-SU-2024:10727-1
RHSA-2020:0165
RHSA-2020:0166
RHSA-2020:0168
RHSA-2020:0171
RHSA-2020:0172
RHSA-2020:1226
RHSA-2020:1735
RHSA-2020_1735
SUSE-SU-2019:3032-1
SUSE-SU-2019:3179-1
SUSE-SU-2019_3032-1
SUSE-SU-2019_3179-1
SUSE-SU-2020:0412-1
SUSE-SU-2020:0439-1
SUSE-SU-2020:1430-1
SUSE-SU-2020:2194-1
SUSE-SU-2020_0412-1
SUSE-SU-2020_0439-1
SUSE-SU-2020_1430-1
SUSE-SU-2020_2194-1
USN-4189-1
USN-4189-2

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Dpdk