<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:42:00 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:8263 — Important: dpdk security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:8263</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dpdk, AlmaLinux:9: dpdk-devel, AlmaLinux:9: dpdk-doc, AlmaLinux:9: dpdk-tools&lt;/p&gt;
&lt;p&gt;The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132)
* DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash (CVE-2021-3839)
* dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service (CVE-2022-28199)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: dpdk, AlmaLinux:9: dpdk-devel, AlmaLinux:9: dpdk-doc, AlmaLinux:9: dpdk-tools&lt;/p&gt;
&lt;p&gt;The dpdk packages provide the Data Plane Development Kit, which is a set of libraries and drivers for fast packet processing in the user space.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs (CVE-2022-2132)
* DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash (CVE-2021-3839)
* dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service (CVE-2022-28199)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:8263</guid>
    </item>
    <item>
      <title>bdu:2022-05391</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05391</link>
      <description>bdu:2022-05391</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05391</guid>
    </item>
    <item>
      <title>certfr-2022-avi-806 — De multiples vulnérabilités ont été découvertes dans les produits Cisco.
Certaines d'entre elles permettent à un attaqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-806</link>
      <description>certfr-2022-avi-806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-806</guid>
    </item>
    <item>
      <title>cisco-sa-mlx5-jbPCrqD8 — Vulnerability in NVIDIA Data Plane Development Kit Affecting Cisco Products: August 2022</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-mlx5-jbpcrqd8</link>
      <description>&lt;p&gt;On August 29, 2022, NVIDIA announced the following vulnerability with a medium impact:&#13;
&#13;
CVE-2022-28199: Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022&#13;
&#13;
For a description of this vulnerability, see Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022 [&amp;#34;https://nvidia.custhelp.com/app/answers/detail/a_id/5389&amp;#34;].&#13;
&#13;
This advisory will be updated as additional information becomes available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On August 29, 2022, NVIDIA announced the following vulnerability with a medium impact:&#13;
&#13;
CVE-2022-28199: Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022&#13;
&#13;
For a description of this vulnerability, see Security Bulletin: NVIDIA Data Plane Development Kit (MLNX_DPDK) - August 2022 [&amp;#34;https://nvidia.custhelp.com/app/answers/detail/a_id/5389&amp;#34;].&#13;
&#13;
This advisory will be updated as additional information becomes available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-mlx5-jbpcrqd8</guid>
    </item>
    <item>
      <title>EUVD-2026-15639</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-15639</link>
      <description>EUVD-2026-15639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-15639</guid>
    </item>
    <item>
      <title>fkie_cve-2022-28199</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-28199</link>
      <description>&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-28199</guid>
    </item>
    <item>
      <title>GHSA-x5mv-h4g3-j3r2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x5mv-h4g3-j3r2</link>
      <description>&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x5mv-h4g3-j3r2</guid>
    </item>
    <item>
      <title>gsd-2022-28199</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-28199</link>
      <description>gsd-2022-28199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-28199</guid>
    </item>
    <item>
      <title>OESA-2022-1965 — dpdk security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2022-1965</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: dpdk, openEuler:20.03-LTS-SP3: dpdk, openEuler:22.03-LTS: dpdk&lt;/p&gt;
&lt;p&gt;DPDK core includes kernel modules, core libraries and tools.testpmd application allows to test fast packet processing environments on arm64 platforms. For instance, it can be used to check that environment can support fast path applications such as 6WINDGate, pktgen, rumptcpip, etc. More libraries are available as extensions in other packages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.(CVE-2022-28199)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: dpdk, openEuler:20.03-LTS-SP3: dpdk, openEuler:22.03-LTS: dpdk&lt;/p&gt;
&lt;p&gt;DPDK core includes kernel modules, core libraries and tools.testpmd application allows to test fast packet processing environments on arm64 platforms. For instance, it can be used to check that environment can support fast path applications such as 6WINDGate, pktgen, rumptcpip, etc. More libraries are available as extensions in other packages.&#13;
&#13;
Security Fix(es):&#13;
&#13;
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.(CVE-2022-28199)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2022-1965</guid>
    </item>
    <item>
      <title>RHSA-2022:6502 — Red Hat Security Advisory: openvswitch2.13 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:6502</link>
      <description>&lt;p&gt;dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:6502</guid>
    </item>
    <item>
      <title>RHSA-2022:8263 — Red Hat Security Advisory: dpdk security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:8263</link>
      <description>&lt;p&gt;DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DPDK: out-of-bounds read/write in vhost_user_set_inflight_fd() may lead to crash dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:8263</guid>
    </item>
    <item>
      <title>SUSE-SU-2022:3390-1 — Security update for dpdk</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2022:3390-1</link>
      <description>&lt;p&gt;Security update for dpdk&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for dpdk&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2022:3390-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-28199</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28199</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: dpdk, Ubuntu:22.04:LTS: dpdk&lt;/p&gt;
&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: dpdk, Ubuntu:22.04:LTS: dpdk&lt;/p&gt;
&lt;p&gt;NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-28199</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1021 — Oracle Communications: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1021</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1021</guid>
    </item>
  </channel>
</rss>
