Skip to content

Conversation

@mwang69
Copy link

@mwang69 mwang69 commented Feb 26, 2025

No description provided.

This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the
vhost-user master exhausts available fd in the vhost-user slave
process, leading to a denial of service.

Reference: https://security-tracker.debian.org/tracker/CVE-2022-0669

Upstream-patch: DPDK/dpdk@af74f7d
@angolini
Copy link
Member

angolini commented Sep 4, 2025

Is this PR still relevant?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants