RHSA-2023:0169: Important: dpdk security update
The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space.Security Fix(es): dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dpdkto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdk-debuginfoto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdk-debugsourceto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdk-develto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdk-docto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdk-toolsto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4 - Upgrade
Upgrade
redhat/dpdkto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4.aa - Upgrade
Upgrade
redhat/dpdk-debuginfoto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4.aa - Upgrade
Upgrade
redhat/dpdk-debugsourceto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4.aa - Upgrade
Upgrade
redhat/dpdk-develto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4.aa - Upgrade
Upgrade
redhat/dpdk-toolsto a version that resolves this vulnerability.Fixed in 20.11-4.el8_4.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0169?
The severity of RHSA-2023:0169 is classified as important.
How do I fix RHSA-2023:0169?
To fix RHSA-2023:0169, you need to update the dpdk packages to version 20.11-4.el8_4.
What vulnerability is addressed by RHSA-2023:0169?
RHSA-2023:0169 addresses a denial of service (DoS) vulnerability when a Vhost header crosses more than two descriptors.
Which packages are affected by RHSA-2023:0169?
RHSA-2023:0169 affects various dpdk packages including dpdk, dpdk-debuginfo, dpdk-devel, and others.
Is there a specific CVE associated with RHSA-2023:0169?
Yes, RHSA-2023:0169 is associated with CVE-2022-2132.