CVE-2019-14818: High severity dpdk (data plane development kit) vulnerability
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhostuser socket, can send specially crafted VRINGSETNUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Other sources
A vulnerability was found in dpdk where a malicious master keep sending VRINGSETNUM message, all the above memory will be leaked, and result a DOS finally since retmalloc() won't allocate any memory.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-14818?
CVE-2019-14818 is a vulnerability in dpdk versions 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4, and 19.x.x before 19.08.1 that can result in a memory leak.
What is the severity of CVE-2019-14818?
CVE-2019-14818 has a severity of 7.5 (high).
How can a malicious attacker exploit CVE-2019-14818?
A malicious master or a container with access to vhost_user socket can send specially crafted VRING_SET_NUM messages to exploit CVE-2019-14818.
How can I fix CVE-2019-14818?
To fix CVE-2019-14818, update to dpdk version 17.11.8, 16.11.10, 18.11.4, or 19.08.1.
Where can I find more information about CVE-2019-14818?
You can find more information about CVE-2019-14818 at the following references: [1] [2] [3].