7.5
CVE-2019-14818
- EPSS 1.14%
- Published 14.11.2019 17:15:14
- Last modified 21.11.2024 04:27:25
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Data is provided by the National Vulnerability Database (NVD)
Dpdk ≫ Data Plane Development Kit Version >= 16.04 < 16.11.10
Dpdk ≫ Data Plane Development Kit Version >= 17.02 < 17.11.8
Dpdk ≫ Data Plane Development Kit Version >= 18.02 < 18.11.4
Dpdk ≫ Data Plane Development Kit Version >= 19.02 < 19.08.1
Redhat ≫ Enterprise Linux Fast Datapath Version7.0
Redhat ≫ Enterprise Linux Fast Datapath Version8.0
Redhat ≫ Virtualization Eus Version4.2
Fedoraproject ≫ Fedora Version31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.14% | 0.775 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
secalert@redhat.com | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-401 Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.