Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 12 Nov 2019 15:04:34 +0000
From: Ferruh Yigit <>
To: dpdk-announce <>
Subject: DPDK security advisory: CVE-2019-14818

A vulnerability was fixed in DPDK.

Some downstream stakeholders were warned in advance in order to coordinate the
release of fixes and reduce the vulnerability window.

A malicious container which has direct access to the vhost-user socket can keep
sending messages which may cause leaking resources until resulting a DOS.

All users of the vhost library are strongly encouraged to upgrade as soon as

Severity: Medium
CVSS scores: 6.8

main repo


18.11.4 (LTS)

17.11.8 (LTS)

16.11.10 (LTS EOL)

Stable Releases download links:
DPDK 19.08.1

DPDK 18.11.4 (LTS)

DPDK 17.11.8 (LTS)

DPDK 16.11.10 (LTS EOL)

DPDK Security Team

Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.