Vulnerability Details CVE-2019-14818
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 76.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-14818
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.04
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.6
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.7
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.8
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.9
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.02.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.6
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.7
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08
-
cpe:2.3:a:redhat:enterprise_linux_fast_datapath:7.0
-
cpe:2.3:a:redhat:enterprise_linux_fast_datapath:8.0
-
cpe:2.3:a:redhat:openstack:10
-
cpe:2.3:a:redhat:virtualization_eus:4.2
-
cpe:2.3:o:fedoraproject:fedora:31