CVE-2022-28199

NameCVE-2022-28199
DescriptionNVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-5222-1
Debian Bugs1019589

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
dpdk (PTS)buster18.11.11-1~deb10u1fixed
buster (security)18.11.11-1~deb10u2fixed
bullseye20.11.10-1~deb11u1fixed
bullseye (security)20.11.6-1~deb11u1fixed
bookworm22.11.4-1~deb12u1fixed
trixie23.11-1fixed
sid23.11.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dpdksourceexperimental22.11~rc2-1
dpdksourcebuster(not affected)
dpdksourcebullseye20.11.6-1~deb11u1DSA-5222-1
dpdksource(unstable)22.11.1-21019589

Notes

[buster] - dpdk <not-affected> (Vulnerable code introduced later)
https://git.dpdk.org/dpdk/commit/?id=60b254e3923d007bcadbb8d410f95ad89a2f13fa (main)
https://git.dpdk.org/dpdk-stable/commit/?id=25c01bd32374b0c3cbc260f3e3872408d749cb45 (v21.11.2)
https://git.dpdk.org/dpdk-stable/commit/?id=ef311075d21b4f68c8ccfc46a00cda7c2a0bf4cc (v20.11.6)
https://git.dpdk.org/dpdk-stable/commit/?id=8b090f2664e9d014cd8fa0fde90597aaf4349e7e (v19.11.13)
https://www.openwall.com/lists/oss-security/2022/08/29/3

Search for package or bug name: Reporting problems