CVE-2022-2132
published 2022-08-31CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted…
PriorityP342high8.6CVSS 3.1
AVNACLPRNUINSCCNINAH
EPSS
1.77%
75.6th percentile
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | dpdk | < dpdk 22.11.1-2 (bookworm) | dpdk 22.11.1-2 (bookworm) |
| dpdk | data_plane_development_kit | < 19.11 | 19.11 |
| dpdk | data_plane_development_kit | >= 20.0 < 20.11 | 20.11 |
| dpdk | data_plane_development_kit | >= 21.0 < 21.11 | 21.11 |
| dpdk | dpdk | >= 0 < 20.11.6-1~deb11u1 | 20.11.6-1~deb11u1 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_fast_datapath | — | — |
| redhat | enterprise_linux_fast_datapath | — | — |
| redhat | enterprise_linux_fast_datapath | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
DPDK vulnerability
vendor_ubuntu·2022-09-13
CVE-2022-2132 DPDK vulnerability
Title: DPDK vulnerability
Summary: DPDK could be made to stop responding if it received specially crafted
network traffic.
It was discovered that DPDK incorrectly handled certain Vhost headers. A
remote attacker could possibly use this issue to cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs
vendor_redhat·2022-08-29·CVSS 8.6
CVE-2022-2132 [HIGH] CWE-770 dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs
dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Statement: In OpenShift Container Platform (OCP) the openvswitch rpm package is consumed from the RHEL Fast Datapath repositories, hence OCP openvswitch components are marked as "Will not fix".
Package: openvswitch (Fast Datapath for RHEL 7) - Not affected
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Not affected
Package: openvswitch2.12 (F
Debian
CVE-2022-2132: dpdk - A permissive list of allowed inputs flaw was found in DPDK. This issue allows a ...
vendor_debian·2022·CVSS 8.6
CVE-2022-2132 [HIGH] CVE-2022-2132: dpdk - A permissive list of allowed inputs flaw was found in DPDK. This issue allows a ...
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Scope: local
bookworm: resolved (fixed in 22.11.1-2)
bullseye: resolved (fixed in 20.11.6-1~deb11u1)
forky: resolved (fixed in 22.11.1-2)
sid: resolved (fixed in 22.11.1-2)
trixie: resolved (fixed in 22.11.1-2)
GHSA
GHSA-m6j8-qrc2-r53c: A permissive list of allowed inputs flaw was found in DPDK
ghsa_unreviewed·2022-09-01
CVE-2022-2132 [HIGH] GHSA-m6j8-qrc2-r53c: A permissive list of allowed inputs flaw was found in DPDK
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
OSV
CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK
osv·2022-08-31·CVSS 8.6
CVE-2022-2132 [HIGH] CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.dpdk.org/show_bug.cgi?id=1031https://bugzilla.redhat.com/show_bug.cgi?id=2099475https://lists.debian.org/debian-lts-announce/2022/09/msg00000.htmlhttps://bugs.dpdk.org/show_bug.cgi?id=1031https://bugzilla.redhat.com/show_bug.cgi?id=2099475https://lists.debian.org/debian-lts-announce/2022/09/msg00000.html
2022-08-31
Published