CVE-2022-28199
published 2022-09-01CVE-2022-28199: NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled…
PriorityP348high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.88%
77.2th percentile
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dpdk | < dpdk 22.11.1-2 (bookworm) | dpdk 22.11.1-2 (bookworm) |
| dpdk | dpdk | >= 0 < 20.11.6-1~deb11u1 | 20.11.6-1~deb11u1 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| dpdk | dpdk | >= 0 < 22.11.1-2 | 22.11.1-2 |
| nvidia | data_plane_development_kit | >= 19.11_1.0.0 < 20.11_5.0.0 | 20.11_5.0.0 |
| nvidia | nvidia_flare | — | — |
| paloalto | cloud_ngfw | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
osv8.6HIGH
vendor_oracle8.6MEDIUM
vendor_cisco6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
Oracle
Oracle Oracle Communications Risk Matrix: Third Party (Dpdk) — CVE-2022-28199
vendor_oracle·2023-04-15·CVSS 8.6
CVE-2022-28199 [MEDIUM] Oracle Oracle Communications Risk Matrix: Third Party (Dpdk) — CVE-2022-28199
Oracle Oracle Communications Risk Matrix: Third Party (Dpdk) vulnerability
CVE: CVE-2022-28199
CVSS: 8.6
Protocol: TCP/IP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Palo Alto
Informational: PAN-OS: Impact of the NVIDIA Dataplane Development Kit (DPDK) Vulnerability CVE-2022-28199
vendor_paloalto·2022-09-14·CVSS 8.6
CVE-2022-28199 [HIGH] CWE-20 Informational: PAN-OS: Impact of the NVIDIA Dataplane Development Kit (DPDK) Vulnerability CVE-2022-28199
Informational: PAN-OS: Impact of the NVIDIA Dataplane Development Kit (DPDK) Vulnerability CVE-2022-28199
The Palo Alto Networks Product Security Assurance team evaluated the NVIDIA Dataplane Development Kit (DPDK) vulnerability (CVE-2022-28199) as it relates to our products.
This vulnerability causes networking stacks that use the NVIDIA distribution of the DPDK to enter an unrecoverable state when processing traffic and results in a denial-of-service (DoS) to the network interface.
Palo Alto Networks VM-Series (virtual) firewalls that have an enabled NVIDIA network interface card use the affected NVIDIA DPDK module on PAN-OS 10.1 and later versions of PAN-OS software but there are no scenarios that enable successful exploitation of this vulnerability in PAN-OS software. As a result, t
Cisco
Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
vendor_cisco·2022-09-07·CVSS 6.5
CVE-2022-28199 [MEDIUM] CWE-390 Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
On August 29, 2022, NVIDIA announced the following vulnerability with a medium impact:
CVE-2022-28199: Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022
For a description of this vulnerability, see Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
Red Hat
dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service
vendor_redhat·2022-08-30·CVSS 6.5
CVE-2022-28199 [MEDIUM] CWE-393 dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service
dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
A vulnerability was found in the DPDK package. Affected versions of this package are vulnerable to denial of service (DoS) attacks, affecting system availability.
Package: dpdk (Fast Datapath for RHEL 7) - Will not fix
Package: openvswitch (Fast Datapath for RHEL 7) - Will not fix
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Out of support scope
Package: openvswitch2.11 (Fast Datapath for RHEL 7) - Out of support sc
Debian
CVE-2022-28199: dpdk - NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a v...
vendor_debian·2022·CVSS 6.5
CVE-2022-28199 [MEDIUM] CVE-2022-28199: dpdk - NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a v...
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
Scope: local
bookworm: resolved (fixed in 22.11.1-2)
bullseye: resolved (fixed in 20.11.6-1~deb11u1)
forky: resolved (fixed in 22.11.1-2)
sid: resolved (fixed in 22.11.1-2)
trixie: resolved (fixed in 22.11.1-2)
Cisco
Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
vendor_cisco·CVSS 3.1
CVE-2022-28199 Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
CVE-2022-28199: Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022
On August 29, 2022, NVIDIA announced the following vulnerability with a medium impact: CVE-2022-28199: Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022 For a description of this vulnerability, see Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022 . This advisory will be updated as additional information becomes available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
CVSS: 3.1
CWE: CWE-390, CWE-390
Bug IDs: CSCwb39904, CSCwb58007, CSCwb39904, CSCwb58007, CSCwb58007
GHSA
GHSA-x5mv-h4g3-j3r2: NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled
ghsa_unreviewed·2022-09-02
CVE-2022-28199 [MEDIUM] CWE-20 GHSA-x5mv-h4g3-j3r2: NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
OSV
CVE-2022-28199: NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled
osv·2022-09-01·CVSS 8.6
CVE-2022-28199 [HIGH] CVE-2022-28199: NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/09/06/2https://nvidia.custhelp.com/app/answers/detail/a_id/5389https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8http://www.openwall.com/lists/oss-security/2022/09/06/2https://nvidia.custhelp.com/app/answers/detail/a_id/5389https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
2022-09-01
Published