CVE-2022-28199
Publication date 1 September 2022
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
Status
Package | Ubuntu Release | Status |
---|---|---|
dpdk | ||
22.04 LTS jammy |
Fixed 21.11.2-0ubuntu0.22.04.1
|
|
20.04 LTS focal |
Fixed 19.11.13-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release |
Notes
mdeslaur
introduced by https://git.dpdk.org/dpdk-stable/commit/?id=88c0733 fixed in the new versions released with USN-5608-1, but not mentioned in the USN itself.
Patch details
Package | Patch details |
---|---|
dpdk |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.5 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |