CVE-2022-0669
published 2022-08-29CVE-2022-0669: A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD…
PriorityP424medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.28%
20.3th percentile
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dpdk | < dpdk 20.11.5-1 (bookworm) | dpdk 20.11.5-1 (bookworm) |
| dpdk | data_plane_development_kit | — | — |
| dpdk | data_plane_development_kit | — | — |
| dpdk | data_plane_development_kit | >= 20.02 < 22.03 | 22.03 |
| dpdk | dpdk | >= 0 < 20.11.5-1~deb11u1 | 20.11.5-1~deb11u1 |
| dpdk | dpdk | >= 0 < 20.11.5-1 | 20.11.5-1 |
| dpdk | dpdk | >= 0 < 20.11.5-1 | 20.11.5-1 |
| dpdk | dpdk | >= 0 < 20.11.5-1 | 20.11.5-1 |
| dpdk | dpdk | >= 0 < 19.11.12-0ubuntu0.20.04.1 | 19.11.12-0ubuntu0.20.04.1 |
| dpdk | dpdk | >= 0 < 21.11.1-0ubuntu0.3 | 21.11.1-0ubuntu0.3 |
| openvswitch | openvswitch | — | — |
| openvswitch | openvswitch | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DPDK vulnerabilities
vendor_ubuntu·2022-05-04·CVSS 7.5
CVE-2022-0669 [HIGH] DPDK vulnerabilities
Title: DPDK vulnerabilities
Summary: Several security issues were fixed in DPDK.
Wenxiang Qian discovered that DPDK incorrectly checked certain payloads. An
attacker could use this issue to cause DPDK to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2021-3839)
It was discovered that DPDK incorrectly handled inflight type messages. An
attacker could possibly use this issue to cause DPDK to consume resources,
leading to a denial of service. (CVE-2022-0669)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dpdk: sending vhost-user-inflight type messages could lead to DoS
vendor_redhat·2022-04-29·CVSS 6.5
CVE-2022-0669 [MEDIUM] CWE-772 dpdk: sending vhost-user-inflight type messages could lead to DoS
dpdk: sending vhost-user-inflight type messages could lead to DoS
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
A flaw was found in dpdk, which allows a malicious primary vhost-user to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the secondary vhost-user. By sending such messages continuously, the primary vhost-user exhausts available fd in the vhost-us
Debian
CVE-2022-0669: dpdk - A flaw was found in dpdk. This flaw allows a malicious vhost-user master to atta...
vendor_debian·2022·CVSS 6.5
CVE-2022-0669 [MEDIUM] CVE-2022-0669: dpdk - A flaw was found in dpdk. This flaw allows a malicious vhost-user master to atta...
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Scope: local
bookworm: resolved (fixed in 20.11.5-1)
bullseye: resolved (fixed in 20.11.5-1~deb11u1)
forky: resolved (fixed in 20.11.5-1)
sid: resolved (fixed in 20.11.5-1)
trixie: resolved (fixed in 20.11.5-1)
OSV
CVE-2022-0669: A flaw was found in dpdk
osv·2022-08-29·CVSS 6.5
CVE-2022-0669 [MEDIUM] CVE-2022-0669: A flaw was found in dpdk
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
GHSA
GHSA-4vw6-hh56-rxvj: A flaw was found in dpdk
ghsa_unreviewed·2022-08-29
CVE-2022-0669 [MEDIUM] GHSA-4vw6-hh56-rxvj: A flaw was found in dpdk
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
OSV
dpdk vulnerabilities
osv·2022-05-04·CVSS 7.5
CVE-2021-3839 [HIGH] dpdk vulnerabilities
dpdk vulnerabilities
Wenxiang Qian discovered that DPDK incorrectly checked certain payloads. An
attacker could use this issue to cause DPDK to crash, resulting in a denial
of service, or possibly execute arbitrary code. (CVE-2021-3839)
It was discovered that DPDK incorrectly handled inflight type messages. An
attacker could possibly use this issue to cause DPDK to consume resources,
leading to a denial of service. (CVE-2022-0669)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2022-0669https://bugs.dpdk.org/show_bug.cgi?id=922https://bugzilla.redhat.com/show_bug.cgi?id=2055793https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227https://security-tracker.debian.org/tracker/CVE-2022-0669https://access.redhat.com/security/cve/CVE-2022-0669https://bugs.dpdk.org/show_bug.cgi?id=922https://bugzilla.redhat.com/show_bug.cgi?id=2055793https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227https://security-tracker.debian.org/tracker/CVE-2022-0669
2022-08-29
Published