Show plain JSON{"acknowledgement": "This issue was discovered by Jason Wang (Red Hat).", "affected_release": [{"advisory": "RHSA-2020:0165", "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath", "package": "openvswitch-0:2.9.0-124.el7fdp", "product_name": "Fast Datapath for Red Hat Enterprise Linux 7", "release_date": "2020-01-21T00:00:00Z"}, {"advisory": "RHSA-2020:0166", "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath", "package": "openvswitch2.11-0:2.11.0-35.el7fdp", "product_name": "Fast Datapath for Red Hat Enterprise Linux 7", "release_date": "2020-01-21T00:00:00Z"}, {"advisory": "RHSA-2020:0168", "cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath", "package": "openvswitch2.12-0:2.12.0-12.el7fdp", "product_name": "Fast Datapath for Red Hat Enterprise Linux 7", "release_date": "2020-01-21T00:00:00Z"}, {"advisory": "RHSA-2020:0171", "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath", "package": "openvswitch2.11-0:2.11.0-35.el8fdp", "product_name": "Fast Datapath for Red Hat Enterprise Linux 8", "release_date": "2020-01-22T00:00:00Z"}, {"advisory": "RHSA-2020:0172", "cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath", "package": "openvswitch2.12-0:2.12.0-12.el8fdp", "product_name": "Fast Datapath for Red Hat Enterprise Linux 8", "release_date": "2020-01-22T00:00:00Z"}, {"advisory": "RHSA-2020:1226", "cpe": "cpe:/a:redhat:rhel_extras_other:7", "package": "dpdk-0:18.11.5-1.el7_8", "product_name": "Red Hat Enterprise Linux 7 Extras", "release_date": "2020-04-01T00:00:00Z"}, {"advisory": "RHSA-2020:1735", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "dpdk-0:19.11-4.el8", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2020-04-28T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "ansible-role-redhat-subscription-0:1.0.4-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-manila-1:6.3.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-octavia-ui-0:1.0.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-tempest-1:18.0.0-13.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openvswitch2.11-0:2.11.0-35.el7fdp", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-barbican-tests-tempest-0:0.1.0-0.20180828144800.b8bf147.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-hardware-0:0.23.0-0.20200117070144.59211cc.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-keystoneauth1-0:3.4.1-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-keystonemiddleware-0:4.22.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-neutron-lib-0:1.13.0-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-novajoin-0:1.3.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-octavia-tests-tempest-0:1.1.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-openstackclient-0:3.14.3-5.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-openstacksdk-0:0.11.4-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-os-testr-0:1.0.1-0.20200218144109.7dd678e.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-os-vif-0:1.9.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-ovsdbapp-0:0.10.4-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-tempestconf-0:2.4.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "rabbitmq-server-0:3.6.15-6.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "rhosp-release-0:13.0.11-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens)", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "ansible-role-redhat-subscription-0:1.0.4-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-manila-1:6.3.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-octavia-ui-0:1.0.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "openstack-tempest-1:18.0.0-13.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-barbican-tests-tempest-0:0.1.0-0.20180828144800.b8bf147.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-hardware-0:0.23.0-0.20200117070144.59211cc.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-keystoneauth1-0:3.4.1-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-keystonemiddleware-0:4.22.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-neutron-lib-0:1.13.0-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-novajoin-0:1.3.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-octavia-tests-tempest-0:1.1.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-openstackclient-0:3.14.3-5.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-openstacksdk-0:0.11.4-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-os-testr-0:1.0.1-0.20200218144109.7dd678e.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-os-vif-0:1.9.2-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-ovsdbapp-0:0.10.4-2.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "python-tempestconf-0:2.4.0-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "rabbitmq-server-0:3.6.15-6.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHBA-2020:0769", "cpe": "cpe:/a:redhat:openstack:13::el7", "package": "rhosp-release-0:13.0.11-1.el7ost", "product_name": "Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS", "release_date": "2020-03-10T00:00:00Z"}, {"advisory": "RHSA-2020:0165", "cpe": "cpe:/o:redhat:enterprise_linux:7::hypervisor", "package": "openvswitch-0:2.9.0-124.el7fdp", "product_name": "Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS", "release_date": "2020-01-21T00:00:00Z"}], "bugzilla": {"description": "dpdk: possible memory leak leads to denial of service", "id": "1737327", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1737327"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.5", "cvss3_scoring_vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "status": "verified"}, "cwe": "CWE-401", "details": ["A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition.", "A flaw was found in dpdk where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of service condition."], "name": "CVE-2019-14818", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:7::fastdatapath", "fix_state": "Will not fix", "package_name": "openvswitch2.10", "product_name": "Fast Datapath for RHEL 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath", "fix_state": "Not affected", "package_name": "openvswitch", "product_name": "Fast Datapath for RHEL 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8::fastdatapath", "fix_state": "Not affected", "package_name": "openvswitch2.10", "product_name": "Fast Datapath for RHEL 8"}, {"cpe": "cpe:/a:redhat:ceph_storage:3", "fix_state": "Not affected", "package_name": "ceph", "product_name": "Red Hat Ceph Storage 3"}, {"cpe": "cpe:/a:redhat:ceph_storage:4", "fix_state": "Affected", "package_name": "ceph", "product_name": "Red Hat Ceph Storage 4"}, {"cpe": "cpe:/a:redhat:openstack:10", "fix_state": "Not affected", "package_name": "dpdk", "product_name": "Red Hat OpenStack Platform 10 (Newton)"}, {"cpe": "cpe:/a:redhat:openstack:10", "fix_state": "Out of support scope", "package_name": "openvswitch", "product_name": "Red Hat OpenStack Platform 10 (Newton)"}, {"cpe": "cpe:/a:redhat:openstack:14", "fix_state": "Out of support scope", "package_name": "openvswitch", "product_name": "Red Hat OpenStack Platform 14 (Rocky)"}], "public_date": "2019-11-12T15:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2019-14818\nhttps://nvd.nist.gov/vuln/detail/CVE-2019-14818\nhttps://bugs.dpdk.org/show_bug.cgi?id=363"], "statement": "The dpdk package within Red Hat OpenStack Platform 10 has been superseded by the version included with RHEL Extras, fixes for dpdk will be consumed from here.", "threat_severity": "Moderate"}