2019-12-28
ALT-BU-2019-4157-1
Branch sisyphus update bulletin.
Closed vulnerabilities
Published: 2019-11-12
BDU:2020-01861
Уязвимость набора библиотек и драйверов для быстрой обработки пакетов dpdk, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2019-11-14
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-14818
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- RHSA-2020:0165
- RHSA-2020:0165
- RHSA-2020:0166
- RHSA-2020:0166
- RHSA-2020:0168
- RHSA-2020:0168
- RHSA-2020:0171
- RHSA-2020:0171
- RHSA-2020:0172
- RHSA-2020:0172
- https://bugs.dpdk.org/show_bug.cgi?id=363
- https://bugs.dpdk.org/show_bug.cgi?id=363
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14818
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14818
- FEDORA-2019-019df9a459
- FEDORA-2019-019df9a459