CVE-2020-10726
20.05.2020, 14:15
A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dpdk | data_plane_development_kit | 𝑥 ≤ 19.11 |
| opensuse | leap | 15.1 |
| oracle | enterprise_communications_broker | 3.1.0 |
| oracle | enterprise_communications_broker | 3.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| dpdk |
| ||||||||||||||||||||||||||
| dpdk-devel |
| ||||||||||||||||||||||||||
| dpdk-thunderx |
| ||||||||||||||||||||||||||
| dpdk-thunderx-devel |
| ||||||||||||||||||||||||||
| dpdk-tools |
| ||||||||||||||||||||||||||
| libdpdk-18_11 |
| ||||||||||||||||||||||||||
| libdpdk-20_0 |
| ||||||||||||||||||||||||||
| libdpdk-25 |
|
Red Hat Enterprise Linux Releases
References