{
  "threat_severity" : "Moderate",
  "public_date" : "2019-11-12T15:00:00Z",
  "bugzilla" : {
    "description" : "dpdk: possible memory leak leads to denial of service",
    "id" : "1737327",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1737327"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-401",
  "details" : [ "A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.", "A flaw was found in dpdk where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition." ],
  "statement" : "The dpdk package within Red Hat OpenStack Platform 10 has been superseded by the version included with RHEL Extras, fixes for dpdk will be consumed from here.",
  "acknowledgement" : "This issue was discovered by Jason Wang (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0165",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath",
    "package" : "openvswitch-0:2.9.0-124.el7fdp"
  }, {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0166",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath",
    "package" : "openvswitch2.11-0:2.11.0-35.el7fdp"
  }, {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 7",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0168",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath",
    "package" : "openvswitch2.12-0:2.12.0-12.el7fdp"
  }, {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 8",
    "release_date" : "2020-01-22T00:00:00Z",
    "advisory" : "RHSA-2020:0171",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8::fastdatapath",
    "package" : "openvswitch2.11-0:2.11.0-35.el8fdp"
  }, {
    "product_name" : "Fast Datapath for Red Hat Enterprise Linux 8",
    "release_date" : "2020-01-22T00:00:00Z",
    "advisory" : "RHSA-2020:0172",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8::fastdatapath",
    "package" : "openvswitch2.12-0:2.12.0-12.el8fdp"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7 Extras",
    "release_date" : "2020-04-01T00:00:00Z",
    "advisory" : "RHSA-2020:1226",
    "cpe" : "cpe:/a:redhat:rhel_extras_other:7",
    "package" : "dpdk-0:18.11.5-1.el7_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2020-04-28T00:00:00Z",
    "advisory" : "RHSA-2020:1735",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dpdk-0:19.11-4.el8"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "ansible-role-redhat-subscription-0:1.0.4-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-manila-1:6.3.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-octavia-ui-0:1.0.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-tempest-1:18.0.0-13.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openvswitch2.11-0:2.11.0-35.el7fdp"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-barbican-tests-tempest-0:0.1.0-0.20180828144800.b8bf147.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-hardware-0:0.23.0-0.20200117070144.59211cc.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-keystoneauth1-0:3.4.1-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-keystonemiddleware-0:4.22.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-neutron-lib-0:1.13.0-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-novajoin-0:1.3.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-octavia-tests-tempest-0:1.1.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstackclient-0:3.14.3-5.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstacksdk-0:0.11.4-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-os-testr-0:1.0.1-0.20200218144109.7dd678e.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-os-vif-0:1.9.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-ovsdbapp-0:0.10.4-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-tempestconf-0:2.4.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "rabbitmq-server-0:3.6.15-6.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens)",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "rhosp-release-0:13.0.11-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "ansible-role-redhat-subscription-0:1.0.4-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-manila-1:6.3.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-octavia-ui-0:1.0.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "openstack-tempest-1:18.0.0-13.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-barbican-tests-tempest-0:0.1.0-0.20180828144800.b8bf147.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-hardware-0:0.23.0-0.20200117070144.59211cc.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-keystoneauth1-0:3.4.1-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-keystonemiddleware-0:4.22.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-neutron-lib-0:1.13.0-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-novajoin-0:1.3.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-octavia-tests-tempest-0:1.1.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstackclient-0:3.14.3-5.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-openstacksdk-0:0.11.4-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-os-testr-0:1.0.1-0.20200218144109.7dd678e.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-os-vif-0:1.9.2-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-ovsdbapp-0:0.10.4-2.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "python-tempestconf-0:2.4.0-1.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "rabbitmq-server-0:3.6.15-6.el7ost"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS",
    "release_date" : "2020-03-10T00:00:00Z",
    "advisory" : "RHBA-2020:0769",
    "cpe" : "cpe:/a:redhat:openstack:13::el7",
    "package" : "rhosp-release-0:13.0.11-1.el7ost"
  }, {
    "product_name" : "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS",
    "release_date" : "2020-01-21T00:00:00Z",
    "advisory" : "RHSA-2020:0165",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::hypervisor",
    "package" : "openvswitch-0:2.9.0-124.el7fdp"
  } ],
  "package_state" : [ {
    "product_name" : "Fast Datapath for RHEL 7",
    "fix_state" : "Will not fix",
    "package_name" : "openvswitch2.10",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7::fastdatapath"
  }, {
    "product_name" : "Fast Datapath for RHEL 8",
    "fix_state" : "Not affected",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
  }, {
    "product_name" : "Fast Datapath for RHEL 8",
    "fix_state" : "Not affected",
    "package_name" : "openvswitch2.10",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8::fastdatapath"
  }, {
    "product_name" : "Red Hat Ceph Storage 3",
    "fix_state" : "Not affected",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:3"
  }, {
    "product_name" : "Red Hat Ceph Storage 4",
    "fix_state" : "Will not fix",
    "package_name" : "ceph",
    "cpe" : "cpe:/a:redhat:ceph_storage:4"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Not affected",
    "package_name" : "dpdk",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Out of support scope",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat OpenStack Platform 14 (Rocky)",
    "fix_state" : "Out of support scope",
    "package_name" : "openvswitch",
    "cpe" : "cpe:/a:redhat:openstack:14"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2019-14818\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-14818\nhttps://bugs.dpdk.org/show_bug.cgi?id=363" ],
  "name" : "CVE-2019-14818",
  "csaw" : false
}