CVE-2022-0669
Title: dpdk vhost-user master fd exhaustion
Denial of Service
Proof Of Concept
No public PoC currently indexed for CVE-2022-0669.
CWE Category
CWE-400
Published Date
Aug 29, 2022
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
6.5
CVSS v3.1
Exploit Probability (EPSS)
0.28%
Vulnerability Summary
CVE-2022-0669: A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Impacted Vendors
Reference Links
https://access.redhat.com/security/cve/CVE-2022-0669
https://bugs.dpdk.org/show_bug.cgi?id=922
https://bugzilla.redhat.com/show_bug.cgi?id=2055793
https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227
https://security-tracker.debian.org/tracker/CVE-2022-0669
https://access.redhat.com/security/cve/CVE-2022-0669
https://bugs.dpdk.org/show_bug.cgi?id=922
https://bugzilla.redhat.com/show_bug.cgi?id=2055793
https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227
https://security-tracker.debian.org/tracker/CVE-2022-0669
CVSS v3.1
Source Entity
[email protected]
Severity
MEDIUM
6.5
Attack Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2022-0669 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
LOCAL
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Affected Stack
No specific products linked.