CVE-2019-14818
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Published:Nov 12, 2019
Last Modified:Nov 21, 2024
EPS:Nov 14, 2019
EPSS Score:0.01137
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Dpdk
Product
Data Plane Development Kit
Dpdk
Data Plane Development Kit
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Enterprise Linux Fast Datapath
Redhat
Enterprise Linux Fast Datapath
Vendor
Redhat
Product
Openstack
Redhat
Openstack
Vendor
Redhat
Product
Rhel Extras Other
Redhat
Rhel Extras Other
Vendor
Redhat
Product
Virtualization Eus
Redhat
Virtualization Eus
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
