dpdk: sending vhost-user-inflight type messages could lead to DoS
Published Aug 29, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.30%
Description
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Affected products
- Vendor n/a Product DPDK Defaultn/a
- Version Affects v19.11-rc1 and later, Fixed in v22.03-rc4.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | DPDK | n/a |
|
Configuration 1
- ≥ 20.02 · < 22.03
- 19.11
- 19.11
- 19.11
- 19.11
- 19.11
- 22.03
- 22.03
- 22.03
Configuration 2
- 2.13.0
- 2.15.0
Configuration 3
- 4.0
No data.
Fast Datapath for Red Hat Enterprise Linux 8
openvswitch2.13-0:2.13.0-180.el8fdp
Fixed · RHSA-2022:4786
Fast Datapath for Red Hat Enterprise Linux 8
openvswitch2.15-0:2.15.0-99.el8fdp
Fixed · RHSA-2022:4787
Fast Datapath for Red Hat Enterprise Linux 8
openvswitch2.16-0:2.16.0-74.el8fdp
Fixed · RHSA-2022:4788
Fast Datapath for RHEL 7
dpdk
Will not fix
Fast Datapath for RHEL 7
openvswitch
Not affected
Fast Datapath for RHEL 7
openvswitch2.11
Not affected
Fast Datapath for RHEL 7
openvswitch2.13
Out of support scope
Fast Datapath for RHEL 7
openvswitch2.15
Out of support scope
Fast Datapath for RHEL 8
openvswitch2.11
Not affected
Fast Datapath for RHEL 8
openvswitch2.17
Not affected
Red Hat Ceph Storage 3
ceph
Out of support scope
Red Hat Ceph Storage 4
ceph
Not affected
Red Hat Enterprise Linux 7
dpdk
Out of support scope
Red Hat Enterprise Linux 8
dpdk
Will not fix
Red Hat Enterprise Linux 9
dpdk
Not affected
Red Hat OpenShift Container Platform 4
openshift4/dpdk-base-rhel8
Affected
Red Hat OpenStack Platform 13 (Queens)
rhosp-openvswitch
Out of support scope
Red Hat Virtualization 4
openvswitch2.10
Not affected
Red Hat Virtualization 4
openvswitch2.11
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Fast Datapath for Red Hat Enterprise Linux 8 | openvswitch2.13-0:2.13.0-180.el8fdp | Fixed | RHSA-2022:4786 |
| Fast Datapath for Red Hat Enterprise Linux 8 | openvswitch2.15-0:2.15.0-99.el8fdp | Fixed | RHSA-2022:4787 |
| Fast Datapath for Red Hat Enterprise Linux 8 | openvswitch2.16-0:2.16.0-74.el8fdp | Fixed | RHSA-2022:4788 |
| Fast Datapath for RHEL 7 | dpdk | Will not fix | n/a |
| Fast Datapath for RHEL 7 | openvswitch | Not affected | n/a |
| Fast Datapath for RHEL 7 | openvswitch2.11 | Not affected | n/a |
| Fast Datapath for RHEL 7 | openvswitch2.13 | Out of support scope | n/a |
| Fast Datapath for RHEL 7 | openvswitch2.15 | Out of support scope | n/a |
| Fast Datapath for RHEL 8 | openvswitch2.11 | Not affected | n/a |
| Fast Datapath for RHEL 8 | openvswitch2.17 | Not affected | n/a |
| Red Hat Ceph Storage 3 | ceph | Out of support scope | n/a |
| Red Hat Ceph Storage 4 | ceph | Not affected | n/a |
| Red Hat Enterprise Linux 7 | dpdk | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | dpdk | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | dpdk | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/dpdk-base-rhel8 | Affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | rhosp-openvswitch | Out of support scope | n/a |
| Red Hat Virtualization 4 | openvswitch2.10 | Not affected | n/a |
| Red Hat Virtualization 4 | openvswitch2.11 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-0669 x_refsource_MISCThird Party AdvisoryVendor Advisory
- https://bugs.dpdk.org/show_bug.cgi?id=922 x_refsource_MISCPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2055793 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-0669
- https://security-tracker.debian.org/tracker/CVE-2022-0669 x_refsource_MISCPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0669
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0669 | x_refsource_MISCThird Party AdvisoryVendor Advisory | |
| https://bugs.dpdk.org/show_bug.cgi?id=922 | x_refsource_MISCPatchVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2055793 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0669 | ||
| https://security-tracker.debian.org/tracker/CVE-2022-0669 | x_refsource_MISCPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0669 |
Change history (0)
No recorded changes yet.