CVE-2022-2132

Severity
8.6HIGH
EPSS
0.8%
top 26.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateSep 13

Description

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages6 packages

NVDdpdk/data_plane_development_kit20.020.11+2
Debiandpdk< 20.11.6-1~deb11u1+3
CVEListV5dpdkdpdk 21.11, dpdk 20.11, dpdk 19.11

Also affects: Debian Linux 10.0, Fedora 36, Enterprise Linux 7.0, 8.0, 9.0, Openshift Container Platform 4.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m6j8-qrc2-r53c: A permissive list of allowed inputs flaw was found in DPDK2022-09-01
OSV
CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK2022-08-31
CVEList
CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK2022-08-31

📋Vendor Advisories

3
Ubuntu
DPDK vulnerability2022-09-13
Red Hat
dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs2022-08-29
Debian
CVE-2022-2132: dpdk - A permissive list of allowed inputs flaw was found in DPDK. This issue allows a ...2022