First published: Thu Feb 17 2022(Updated: )
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openvswitch2.13 | <0:2.13.0-180.el8fd | 0:2.13.0-180.el8fd |
redhat/openvswitch2.15 | <0:2.15.0-99.el8fd | 0:2.15.0-99.el8fd |
redhat/openvswitch2.16 | <0:2.16.0-74.el8fd | 0:2.16.0-74.el8fd |
Dpdk Data Plane Development Kit | >=20.02<22.03 | |
Dpdk Data Plane Development Kit | =19.11 | |
Dpdk Data Plane Development Kit | =19.11-rc1 | |
Dpdk Data Plane Development Kit | =19.11-rc2 | |
Dpdk Data Plane Development Kit | =19.11-rc3 | |
Dpdk Data Plane Development Kit | =19.11-rc4 | |
Dpdk Data Plane Development Kit | =22.03-rc1 | |
Dpdk Data Plane Development Kit | =22.03-rc2 | |
Dpdk Data Plane Development Kit | =22.03-rc3 | |
Openvswitch Openvswitch | =2.13.0 | |
Openvswitch Openvswitch | =2.15.0 | |
Redhat Openshift Container Platform | =4.0 | |
redhat/dpdk | <22.03 | 22.03 |
debian/dpdk | 20.11.10-1~deb11u1 20.11.6-1~deb11u1 22.11.5-1~deb12u1 23.11.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2022-0669.
The severity of CVE-2022-0669 is medium.
The affected software includes dpdk, openvswitch2.13, openvswitch2.15, and openvswitch2.16.
A malicious primary vhost-user can exploit CVE-2022-0669 by attaching an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the secondary vhost-user.
Yes, the remedy for dpdk is version 22.03 and for openvswitch2.13 it is version 0:2.13.0-180.el8fd, for openvswitch2.15 it is version 0:2.15.0-99.el8fd, and for openvswitch2.16 it is version 0:2.16.0-74.el8fd.