PT-2019-5188 · Intel+5 · Dpdk+5
Published
2019-11-12
·
Updated
2024-06-15
·
CVE-2019-14818
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
dpdk versions 16.x.x through 16.11.9
dpdk versions 17.x.x through 17.11.7
dpdk versions 18.x.x through 18.11.3
dpdk versions 19.x.x through 19.08.0
Description
The issue is related to an uncontrolled resource consumption in the dpdk library and driver set, which can be exploited by a remote attacker to cause a denial of service by sending specially crafted
VRING SET NUM messages. This can result in a memory leak, including file descriptors, when a malicious master or a container with access to the vhost user socket sends these messages.Recommendations
For dpdk versions 16.x.x through 16.11.9, update to version 16.11.10 or later.
For dpdk versions 17.x.x through 17.11.7, update to version 17.11.8 or later.
For dpdk versions 18.x.x through 18.11.3, update to version 18.11.4 or later.
For dpdk versions 19.x.x through 19.08.0, update to version 19.08.1 or later.
Fix
DoS
Memory Leak
Resource Exhaustion
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Suse
Ubuntu
Dpdk