CVE-2022-28199: NVIDIA Data Plane Development Kit

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

Affected products

  • NVIDIA Data Plane Development Kit: from 19.11_1.0.0, before 20.11_5.0.0 (fixed in 20.11_5.0.0)

Published 2022-09-01. Last modified 2026-06-17.