An update for dpdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: dpdk security update Advisory ID: RHSA-2023:0168-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0168 Issue date: 2023-01-16 CVE Names: CVE-2022-2132 ==================================================================== 1. Summary: An update for dpdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, noarch, ppc64le, x86_64 3. Description: The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space. Security Fix(es): * dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2099475 - CVE-2022-2132 dpdk: DoS when a Vhost header crosses more than two descriptors and exhaustsall mbufs 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): Source: dpdk-18.11.2-5.el8_1.src.rpm aarch64: dpdk-18.11.2-5.el8_1.aarch64.rpm dpdk-debuginfo-18.11.2-5.el8_1.aarch64.rpm dpdk-debugsource-18.11.2-5.el8_1.aarch64.rpm dpdk-devel-18.11.2-5.el8_1.aarch64.rpm dpdk-devel-debuginfo-18.11.2-5.el8_1.aarch64.rpm dpdk-tools-18.11.2-5.el8_1.aarch64.rpm noarch: dpdk-doc-18.11.2-5.el8_1.noarch.rpm ppc64le: dpdk-18.11.2-5.el8_1.ppc64le.rpm dpdk-debuginfo-18.11.2-5.el8_1.ppc64le.rpm dpdk-debugsource-18.11.2-5.el8_1.ppc64le.rpm dpdk-devel-18.11.2-5.el8_1.ppc64le.rpm dpdk-devel-debuginfo-18.11.2-5.el8_1.ppc64le.rpm dpdk-tools-18.11.2-5.el8_1.ppc64le.rpm x86_64: dpdk-18.11.2-5.el8_1.x86_64.rpm dpdk-debuginfo-18.11.2-5.el8_1.x86_64.rpm dpdk-debugsource-18.11.2-5.el8_1.x86_64.rpm dpdk-devel-18.11.2-5.el8_1.x86_64.rpm dpdk-devel-debuginfo-18.11.2-5.el8_1.x86_64.rpm dpdk-tools-18.11.2-5.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2132 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY8UoQNzjgjWX9erEAQhI2w//Rp5ODsEUvVZ1xJjSB9w2PMi+ha1gqLg+ smBl+kBkHC0lxjyyS9QJ+yhzdW6vauLIdWlL5FX4lr2EiPgElBNoICJEVZ63i5Sp BliQTMDfYJnjVxc+QtkzL3/qGme9BnF2PmoP563La5ud7g1o5pYJrfePhEil56Mv KFQWAme6Yww/nNwnZCEtCFLHncpWAms2pLrPf/hLltb+D36+fc5ZhUY47mTQ/cXw 8LRWOjRB08NXotWdKBopc57PN7Ik8zSW8ORnGOmhGOUmiQjyTddvU3MMa5h+M262 1U27bwoPDnkAaQD8nzumEfHc05UnZCvu5+mxyLeNn8x1jcWFzYla1Y/wMY5SwXU7 qWmN2WhxsW76HAp0KJ+2Np33rxiR2r4+s3ww0NBnuikfRT5QbU5cCd5T8hUmrxQU 2y/ZnFAfDI0tii+CfVXKlHRHHV6TjiPwpG3JorTBz1CwoYjmL/xDvS9u1KHxnC6E mm0fJAkFwmDg8YqJ56JYLMGOOxnESjqRpb3/5FUnQYf8uglJ5pkc0ryRqE7Ki5/S PocJo3BBZ56WjawtsSnaQPn3Ex1HMqjNxDJhKaPSQ1o/KuNKT6CUVltzsD1Sn5Ny 5n+1Peis7PIgF9QPQGgaie1pwuE1JDJiYNfqkPXU+BovZZHsAPDR1hW4jftHpQDN bgTT5U4dUxA=4h8r -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: dpdk security update Advisory ID: RHSA-2023:0167-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2023:0167 Issue date: 2023-01-16 CVE Names: CVE-2022-2132 ==================================================================== 1. Summary: An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux 7 Extras - noarch, ppc64le, x86_64 3. Description: The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space. Security Fix(es): * dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2099475 - CVE-2022-2132 dpdk: DoS when a Vhost header crosses more than two descriptors and exhaustsall mbufs 6. Package List: Red Hat Enterprise Linux 7 Extras: Source: dpdk-18.11.8-2.el7_9.src.rpm noarch: dpdk-doc-18.11.8-2.el7_9.noarch.rpm ppc64le: dpdk-18.11.8-2.el7_9.ppc64le.rpm dpdk-debuginfo-18.11.8-2.el7_9.ppc64le.rpm dpdk-devel-18.11.8-2.el7_9.ppc64le.rpm dpdk-tools-18.11.8-2.el7_9.ppc64le.rpm x86_64: dpdk-18.11.8-2.el7_9.x86_64.rpm dpdk-debuginfo-18.11.8-2.el7_9.x86_64.rpm dpdk-devel-18.11.8-2.el7_9.x86_64.rpm dpdk-tools-18.11.8-2.el7_9.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-2132 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY8UoPtzjgjWX9erEAQh1Dw//UEDtp3cMPbD4oj4U7MLwoeDAlfu1waWD XM+IaeNQCAQh3/LAWLqIBWIYHnpH40KUx6eGq+wqgiHaT+P8wjWjSjHQ9LNOfToj g0QQtEw0ho4N8MoKOarAdCNG3SCNCWqYI7WzK5sbBehpnH6CTiT4HBDQjXQL17wj tEYwypx8BxqlYK4M+i+wSaHgQpm97rQbcuGtL8Kq3DitjrXtlLZcfS4OZ/05/jRa iFeEm1Crf6a3IIBgQpElFd0Geneb73XOWjcFDIBK/NMcJ7oO23NWKAyXMdeG46oo IhsoJ3mLWghvq2nOxsUXr+wDLA/dL7z85dvTaFG9FN/+TOj1cjgg/jQ+67UOPpJS +R3i3147B55NksxI4pBFqopJOwxi2TFCY1+1LAFpMSon+RWwDI/hEb7ZjOIz3KAZ z2+YDXAtpEUEKM0F50IsJsXJ+UxIddY4PjyXY1jooOOI5qsYLbrzazT1s/1oSl1N Zc+wVBwr4xvvd2wELOSomhZA8FqM9Phv8LXHYMCNtDjyOEA/VO8e7TXdJqs+exP7 O+akEmp22LcogkcTBsABitvyHPdX2ne4z5u8a77FRsUDlqwk27SnWnxThSYDTDSP ivlIK941glqRvxXmUs52Iq+HlTXkJj34ZIxbs/cgsY2QyIGGOhHhNoc//CdZbwr5 uyxula2OApU=ycGV -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dpdk ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3356-1 Rating: important References: #1202903 Cross-References: CVE-2022-2132 CVSS scores: CVE-2022-2132 (NVD) : 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVE-2022-2132 (SUSE): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server for SAP 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dpdk fixes the following issues: - CVE-2022-2132: Fixed DoS when a vhost header crosses more than two descriptors and exhausts all mbufs (bsc#1202903). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-3356=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2022-3356=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-3356=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-3356=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): dpdk-18.11.9-150000.3.32.2 dpdk-debuginfo-18.11.9-150000.3.32.2 dpdk-debugsource-18.11.9-150000.3.32.2 dpdk-devel-18.11.9-150000.3.32.2 dpdk-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-tools-18.11.9-150000.3.32.2 dpdk-tools-debuginfo-18.11.9-150000.3.32.2 libdpdk-18_11-18.11.9-150000.3.32.2 libdpdk-18_11-debuginfo-18.11.9-150000.3.32.2 - SUSE Linux Enterprise Server 15-LTSS (aarch64): dpdk-18.11.9-150000.3.32.2 dpdk-debuginfo-18.11.9-150000.3.32.2 dpdk-debugsource-18.11.9-150000.3.32.2 dpdk-devel-18.11.9-150000.3.32.2 dpdk-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-thunderx-18.11.9-150000.3.32.2 dpdk-thunderx-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-debugsource-18.11.9-150000.3.32.2 dpdk-thunderx-devel-18.11.9-150000.3.32.2 dpdk-thunderx-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-thunderx-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-tools-18.11.9-150000.3.32.2 dpdk-tools-debuginfo-18.11.9-150000.3.32.2 libdpdk-18_11-18.11.9-150000.3.32.2 libdpdk-18_11-debuginfo-18.11.9-150000.3.32.2 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): dpdk-18.11.9-150000.3.32.2 dpdk-debuginfo-18.11.9-150000.3.32.2 dpdk-debugsource-18.11.9-150000.3.32.2 dpdk-devel-18.11.9-150000.3.32.2 dpdk-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-tools-18.11.9-150000.3.32.2 dpdk-tools-debuginfo-18.11.9-150000.3.32.2 libdpdk-18_11-18.11.9-150000.3.32.2 libdpdk-18_11-debuginfo-18.11.9-150000.3.32.2 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64): dpdk-thunderx-18.11.9-150000.3.32.2 dpdk-thunderx-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-debugsource-18.11.9-150000.3.32.2 dpdk-thunderx-devel-18.11.9-150000.3.32.2 dpdk-thunderx-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-thunderx-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): dpdk-18.11.9-150000.3.32.2 dpdk-debuginfo-18.11.9-150000.3.32.2 dpdk-debugsource-18.11.9-150000.3.32.2 dpdk-devel-18.11.9-150000.3.32.2 dpdk-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-tools-18.11.9-150000.3.32.2 dpdk-tools-debuginfo-18.11.9-150000.3.32.2 libdpdk-18_11-18.11.9-150000.3.32.2 libdpdk-18_11-debuginfo-18.11.9-150000.3.32.2 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64): dpdk-thunderx-18.11.9-150000.3.32.2 dpdk-thunderx-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-debugsource-18.11.9-150000.3.32.2 dpdk-thunderx-devel-18.11.9-150000.3.32.2 dpdk-thunderx-devel-debuginfo-18.11.9-150000.3.32.2 dpdk-thunderx-kmp-default-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 dpdk-thunderx-kmp-default-debuginfo-18.11.9_k4.12.14_150000.150.98-150000.3.32.2 References: https://www.suse.com/security/cve/CVE-2022-2132.html https://bugzilla.suse.com/1202903 . SUSE Security Update for dpdk CVE-2022-2133 addresses severe DoS vulnerabilities, Classification: high importance. Full patch information enclosed.. SUSE Linux, dpdk Update, Linux Security Patch, DoS Issue. . Severity: Important. LinuxSecurity.com Team
An update for dpdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: dpdk security, bug fix, and enhancement update Advisory ID: RHSA-2020:1735-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:1735 Issue date: 2020-04-28 CVE Names: CVE-2019-14818 ==================================================================== 1. Summary: An update for dpdk is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, x86_64 3. Description: The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space. The following packages have been upgraded to a later upstream version: dpdk (19.11). (BZ#1773889) Security Fix(es): * dpdk: possible memory leak leads to denial of service (CVE-2019-14818) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section. 4. Solution: For details on how to apply this update,which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1737327 - CVE-2019-14818 dpdk: possible memory leak leads to denial of service 1755538 - Use hardening specs to build dpdk-pmdinfogen 1773889 - [Rebase] Rebase DPDK to 19.11 1779229 - Remove dpdk-pdump and dpdk-pmdinfo from dpdk and dpdk-tools packages 1805140 - Remove mlx{4,5} glue library 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: dpdk-19.11-4.el8.src.rpm aarch64: dpdk-19.11-4.el8.aarch64.rpm dpdk-debuginfo-19.11-4.el8.aarch64.rpm dpdk-debugsource-19.11-4.el8.aarch64.rpm dpdk-devel-19.11-4.el8.aarch64.rpm dpdk-devel-debuginfo-19.11-4.el8.aarch64.rpm dpdk-tools-19.11-4.el8.aarch64.rpm noarch: dpdk-doc-19.11-4.el8.noarch.rpm ppc64le: dpdk-19.11-4.el8.ppc64le.rpm dpdk-debuginfo-19.11-4.el8.ppc64le.rpm dpdk-debugsource-19.11-4.el8.ppc64le.rpm dpdk-devel-19.11-4.el8.ppc64le.rpm dpdk-devel-debuginfo-19.11-4.el8.ppc64le.rpm dpdk-tools-19.11-4.el8.ppc64le.rpm x86_64: dpdk-19.11-4.el8.x86_64.rpm dpdk-debuginfo-19.11-4.el8.x86_64.rpm dpdk-debugsource-19.11-4.el8.x86_64.rpm dpdk-devel-19.11-4.el8.x86_64.rpm dpdk-devel-debuginfo-19.11-4.el8.x86_64.rpm dpdk-tools-19.11-4.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-14818 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.2_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXqhWDdzjgjWX9erEAQh3yhAAoyFQ5qoBstMPdSWvAZSscjjZp2UZomqD T9OVTa2xuFPFRkkzKuVoF0ZEaFxyV3RRR8WQi7uYeqPBbu0Ps5tRZFxAoKcKeQ0h omEAyspG3V90cYB/6UQEoXfARlZLQ14XQgdGaEA0TpxsqDWdssLUOIg53vE0sOpD TcORnoRQ3YN5aYRmXdESCZES3SU3XcaqFOEwWechbjGAJ4qgGJbPwuw7du/Xf6Og LJhO0kkiZWAaexRf6a8W459IK8NcDwHvn/Z+OZ4qPBED78Tw9NNtpyLDjN9d+jt4 PtCrTAev7It2tT2uoXP9yB5R2RrOkYqsS7TkugDc0H88aVPl2LzMeFVC0Qx2wAQY fm72JoCTra04x7rQx1Z+qZOczm4Zfi9Le2B3J0RXytEBL8om1kZyguhzJ2TeFOKl TdIQ1xFe81+zugcYTeHGJLGoGYPjC5HuwDqsyvwUDrsW2zWsESanUHTSDjxxJrZg Co8UCIqYXYXBtaQNSsWxDGTUmjt5+gAWJaObU7g6mxtrcfKXA0Nh2datOVJHhGR9 qlDVNhTMt7eFR7acYSr7ebrdwV0+MgtSwLNed1wz5Xgsr+g5oYb9pe4NKGIPQzjP /Y2mkurO2GT5j8r10W+pbaPu7d5NB5E/NUUAFCrSp2hzZStCwldBmsMymGVJS2SY iofayFudKMA=HSBA -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.