CVE-2022-0669: Medium severity DPDK Data Plane Development Kit vulnerability
A flaw was found in dpdk, which allows a malicious primary vhost-user to attach an unexpected number of fds as ancillary data to VHOSTUSERGETINFLIGHTFD / VHOSTUSERSETINFLIGHTFD messages that are not closed by the secondary vhost-user. By sending such messages continuously, the primary vhost-user exhausts available fd in the vhost-user standby process, leading to a denial of service.
Other sources
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOSTUSERGETINFLIGHTFD / VHOSTUSERSETINFLIGHTFD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
It’s an issue in the handling of vhost-user-inf light type messages. A malicious vhost-user master can attach an unexpected number of fds as ancillary data to VHOSTUSERGETINFLIGHTFD / VHOSTUSERSETINFLIGHTFD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master could exhaust available fd in the vhost-user slave process and lead to a DoS.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID of this flaw in dpdk?
The vulnerability ID is CVE-2022-0669.
What is the severity of CVE-2022-0669?
The severity of CVE-2022-0669 is medium.
Which software is affected by CVE-2022-0669?
The affected software includes dpdk, openvswitch2.13, openvswitch2.15, and openvswitch2.16.
How can a malicious primary vhost-user exploit CVE-2022-0669?
A malicious primary vhost-user can exploit CVE-2022-0669 by attaching an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the secondary vhost-user.
Are there any remedies available for CVE-2022-0669?
Yes, the remedy for dpdk is version 22.03 and for openvswitch2.13 it is version 0:2.13.0-180.el8fd, for openvswitch2.15 it is version 0:2.15.0-99.el8fd, and for openvswitch2.16 it is version 0:2.16.0-74.el8fd.