RHSA-2023:0170: Important: dpdk security update
The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space.Security Fix(es): dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/dpdkto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdk-debuginfoto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdk-debugsourceto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdk-develto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdk-docto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdk-toolsto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6 - Upgrade
Upgrade
redhat/dpdkto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6.aa - Upgrade
Upgrade
redhat/dpdk-debuginfoto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6.aa - Upgrade
Upgrade
redhat/dpdk-debugsourceto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6.aa - Upgrade
Upgrade
redhat/dpdk-develto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6.aa - Upgrade
Upgrade
redhat/dpdk-toolsto a version that resolves this vulnerability.Fixed in 21.11-2.el8_6.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2023:0170?
The severity of RHSA-2023:0170 is classified as Important due to the denial of service vulnerability that can be exploited.
How do I fix RHSA-2023:0170?
To fix RHSA-2023:0170, update the dpdk packages to version 21.11-2.el8_6 or later.
What is the impact of the vulnerability in RHSA-2023:0170?
The impact of the vulnerability in RHSA-2023:0170 is that it can lead to denial of service if a Vhost header crosses more than two descriptors and exhausts all mbufs.
Which packages are affected by RHSA-2023:0170?
The affected packages under RHSA-2023:0170 include dpdk, dpdk-devel, dpdk-tools, and related debug information packages.
Is there a specific version required to mitigate RHSA-2023:0170?
Yes, to mitigate RHSA-2023:0170, you should update your dpdk packages to version 21.11-2.el8_6.