CVE-2019-14818
published 2019-11-14CVE-2019-14818: A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.81%
85.0th percentile
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dpdk | < dpdk 18.11.4-1 (bookworm) | dpdk 18.11.4-1 (bookworm) |
| dpdk | data_plane_development_kit | >= 16.04 < 16.11.10 | 16.11.10 |
| dpdk | data_plane_development_kit | >= 17.02 < 17.11.8 | 17.11.8 |
| dpdk | data_plane_development_kit | >= 18.02 < 18.11.4 | 18.11.4 |
| dpdk | data_plane_development_kit | >= 19.02 < 19.08.1 | 19.08.1 |
| dpdk | dpdk | — | — |
| dpdk | dpdk | — | — |
| dpdk | dpdk | — | — |
| dpdk | dpdk | — | — |
| dpdk | dpdk | >= 0 < 18.11.4-1 | 18.11.4-1 |
| dpdk | dpdk | >= 0 < 18.11.4-1 | 18.11.4-1 |
| dpdk | dpdk | >= 0 < 18.11.4-1 | 18.11.4-1 |
| dpdk | dpdk | >= 0 < 18.11.4-1 | 18.11.4-1 |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux_fast_datapath | — | — |
| redhat | enterprise_linux_fast_datapath | — | — |
| redhat | openstack | — | — |
| redhat | virtualization_eus | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DPDK vulnerability
vendor_ubuntu·2019-11-13
CVE-2019-14818 DPDK vulnerability
Title: DPDK vulnerability
Summary: DPDK could be made to consume resources if it received specially crafted
input.
Jason Wang discovered that DPDK incorrectly handled certain messages. An
attacker in a malicious container could possibly use this issue to cause
DPDK to leak resources, resulting in a denial of service.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Red Hat
dpdk: possible memory leak leads to denial of service
vendor_redhat·2019-11-12·CVSS 7.5
CVE-2019-14818 [HIGH] CWE-401 dpdk: possible memory leak leads to denial of service
dpdk: possible memory leak leads to denial of service
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
A flaw was found in dpdk where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Statement: The dpdk package within Red Hat OpenStack Platform 10 has been superseded by the version included with
Debian
CVE-2019-14818: dpdk - A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11....
vendor_debian·2019·CVSS 7.5
CVE-2019-14818 [HIGH] CVE-2019-14818: dpdk - A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11....
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Scope: local
bookworm: resolved (fixed in 18.11.4-1)
bullseye: resolved (fixed in 18.11.4-1)
forky: resolved (fixed in 18.11.4-1)
sid: resolved (fixed in 18.11.4-1)
trixie: resolved (fixed in 18.11.4-1)
GHSA
GHSA-c968-9rc6-v8jv: A flaw was found in all dpdk version 17
ghsa_unreviewed·2022-05-24
CVE-2019-14818 [MEDIUM] CWE-401 GHSA-c968-9rc6-v8jv: A flaw was found in all dpdk version 17
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
OSV
CVE-2019-14818: A flaw was found in all dpdk version 17
osv·2019-11-14·CVSS 7.5
CVE-2019-14818 [HIGH] CVE-2019-14818: A flaw was found in all dpdk version 17
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14818 openvswitch: dpdk: possible memory leak leads to denial of service [openstack-rdo]
bugzilla·2019-11-13·CVSS 7.5
CVE-2019-14818 [HIGH] CVE-2019-14818 openvswitch: dpdk: possible memory leak leads to denial of service [openstack-rdo]
CVE-2019-14818 openvswitch: dpdk: possible memory leak leads to denial of service [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
dpdk is not long
Bugzilla
CVE-2019-14818 dpdk: possible memory leak leads to denial of service [fedora-all]
bugzilla·2019-11-13·CVSS 7.5
CVE-2019-14818 [HIGH] CVE-2019-14818 dpdk: possible memory leak leads to denial of service [fedora-all]
CVE-2019-14818 dpdk: possible memory leak leads to denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2019-14818 dpdk: possible memory leak leads to denial of service
bugzilla·2019-08-05·CVSS 7.5
CVE-2019-14818 [HIGH] CVE-2019-14818 dpdk: possible memory leak leads to denial of service
CVE-2019-14818 dpdk: possible memory leak leads to denial of service
A vulnerability was found in dpdk where a malicious master keep sending VRING_SET_NUM message, all the above memory will be leaked, and result a DOS finally since ret_malloc() won't allocate any memory.
Discussion:
Acknowledgments:
Name: Jason Wang (Red Hat)
---
Statement:
The dpdk package within Red Hat OpenStack Platform 10 has been superseded by the version included with RHEL Extras, fixes for dpdk will be consumed from here.
---
External References:
https://bugs.dpdk.org/show_bug.cgi?id=363
---
Commits:
main repo
https://git.dpdk.org/dpdk/commit/?id=612e17cf6d7b
https://git.dpdk.org/dpdk/commit/?id=bf472259dde6
19.08.1
https://git.dpdk.org/dpdk-stable/commit/?h=19.08&id=fa674d08985f
https://git.dpdk.org/d
https://access.redhat.com/errata/RHSA-2020:0165https://access.redhat.com/errata/RHSA-2020:0166https://access.redhat.com/errata/RHSA-2020:0168https://access.redhat.com/errata/RHSA-2020:0171https://access.redhat.com/errata/RHSA-2020:0172https://bugs.dpdk.org/show_bug.cgi?id=363https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14818https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULJ3C7OVBOEVDGSHYC3VCLSUHANGTFFP/https://access.redhat.com/errata/RHSA-2020:0165https://access.redhat.com/errata/RHSA-2020:0166https://access.redhat.com/errata/RHSA-2020:0168https://access.redhat.com/errata/RHSA-2020:0171https://access.redhat.com/errata/RHSA-2020:0172https://bugs.dpdk.org/show_bug.cgi?id=363https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14818https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ULJ3C7OVBOEVDGSHYC3VCLSUHANGTFFP/
2019-11-14
Published