A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2099475 | issue tracking exploit third party advisory |
https://bugs.dpdk.org/show_bug.cgi?id=1031 | issue tracking patch vendor advisory exploit |
https://lists.debian.org/debian-lts-announce/2022/09/msg00000.html | third party advisory mailing list |