suse · CVE-2019-14818

Quick triage

Priority: medium Published: 2021-05-30 14:30:35 UTC Updated: 2026-03-05 06:11:22 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-14818 severity moderate: SUSE including 102 source package names (dpdk, dpdk-16.11.9-11.3.2, …), 147 product×package rows across 34 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 5, … (34 product lines)): Fixed 140, Known Not Affected 7.

Description:

A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.

cvelogic Threat Intelligence