CVE-2019-14818: Dpdk Data Plane Development Kit
High severity, CVSS 7.5. EPSS: 2.8% chance of exploitation in the next 30 days.
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.
Affected products
- Dpdk Data Plane Development Kit: from 16.04, before 16.11.10 (fixed in 16.11.10); from 17.02, before 17.11.8 (fixed in 17.11.8); from 18.02, before 18.11.4 (fixed in 18.11.4); from 19.02, before 19.08.1 (fixed in 19.08.1)
- Fedoraproject Fedora: version 31 only
- Red Hat Enterprise Linux Fast Datapath: version 7.0 only; version 8.0 only
- Red Hat Openstack: version 10 only
- Red Hat Virtualization Eus: version 4.2 only
Published 2019-11-14. Last modified 2026-06-17.