CVE-2022-0669Uncontrolled Resource Consumption in Data Plane Development KIT

Severity
6.5MEDIUMNVD
OSV7.5
EPSS
0.2%
top 63.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29

Description

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:HExploitability: 2.0 | Impact: 4.0

Affected Packages5 packages

NVDdpdk/data_plane_development_kit20.0222.03+2
Debiandpdk/dpdk< 20.11.5-1~deb11u1+3
Ubuntudpdk/dpdk< 19.11.12-0ubuntu0.20.04.1+1
CVEListV5dpdk/dpdkAffects v19.11-rc1 and later, Fixed in v22.03-rc4.
NVDopenvswitch/openvswitch2.13.0, 2.15.0+1

Also affects: Openshift Container Platform 4.0

Patches

🔴Vulnerability Details

4
CVEList
CVE-2022-0669: A flaw was found in dpdk2022-08-29
OSV
CVE-2022-0669: A flaw was found in dpdk2022-08-29
GHSA
GHSA-4vw6-hh56-rxvj: A flaw was found in dpdk2022-08-29
OSV
dpdk vulnerabilities2022-05-04

📋Vendor Advisories

3
Ubuntu
DPDK vulnerabilities2022-05-04
Red Hat
dpdk: sending vhost-user-inflight type messages could lead to DoS2022-04-29
Debian
CVE-2022-0669: dpdk - A flaw was found in dpdk. This flaw allows a malicious vhost-user master to atta...2022
CVE-2022-0669 — Uncontrolled Resource Consumption | cvebase