cbcvebase.
CVE-2019-14818
published 2019-11-14

CVE-2019-14818: A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandpdk< dpdk 18.11.4-1 (bookworm)dpdk 18.11.4-1 (bookworm)
dpdkdata_plane_development_kit>= 16.04 < 16.11.1016.11.10
dpdkdata_plane_development_kit>= 17.02 < 17.11.817.11.8
dpdkdata_plane_development_kit>= 18.02 < 18.11.418.11.4
dpdkdata_plane_development_kit>= 19.02 < 19.08.119.08.1
dpdkdpdk
dpdkdpdk
dpdkdpdk
dpdkdpdk
dpdkdpdk>= 0 < 18.11.4-118.11.4-1
dpdkdpdk>= 0 < 18.11.4-118.11.4-1
dpdkdpdk>= 0 < 18.11.4-118.11.4-1
dpdkdpdk>= 0 < 18.11.4-118.11.4-1
fedoraprojectfedora
redhatenterprise_linux_fast_datapath
redhatenterprise_linux_fast_datapath
redhatopenstack
redhatvirtualization_eus

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH