dpdk data-plane-development-kit CVE-2019-14818 vulnerability in Dpdk and Other Products
Published on November 14, 2019

product logo product logo product logo
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory Vendor Advisory NVD

Weakness Type

What is a Memory Leak Vulnerability?

The software does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory. This is often triggered by improper handling of malformed data or unexpectedly interrupted sessions. In some languages, developers are responsible for tracking memory allocation and releasing the memory. If there are no more pointers or references to the memory, then it can no longer be tracked and identified for release.

CVE-2019-14818 has been classified to as a Memory Leak vulnerability or weakness.


Products Associated with CVE-2019-14818

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-14818 are published in these products:

 
 
 
 
 
 

Affected Versions

dpdk:

Exploit Probability

EPSS
1.14%
Percentile
78.08%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.