Back

HIGH

dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs

Published Aug 31, 2022

Description

A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.

Affected products

Remediation

Red Hat statement

In OpenShift Container Platform (OCP) the openvswitch rpm package is consumed from the RHEL Fast Datapath repositories, hence OCP openvswitch components are marked as "Will not fix".

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 31, 2022
Updated Aug 3, 2024
Reserved Jun 20, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 29, 2022