{"id":"CVE-2022-0669","details":"A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.","modified":"2026-07-15T00:26:34.567905Z","published":"2022-08-29T14:03:04Z","related":["SUSE-SU-2022:1892-1","SUSE-SU-2022:2273-1","openSUSE-SU-2024:12039-1"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-400"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0669.json","unresolved_ranges":[{"extracted_events":[{"introduced":"Affects v19.11-rc1 and later, Fixed in v22.03-rc4."},{"last_affected":"Affects v19.11-rc1 and later, Fixed in v22.03-rc4."}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2022-0669"},{"type":"WEB","url":"https://bugs.dpdk.org/show_bug.cgi?id=922"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2022-0669"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0669.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0669"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2055793"},{"type":"FIX","url":"https://github.com/DPDK/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dpdk/dpdk","events":[{"introduced":"d7142fbae16f185e11bfa44be061399afc40a1be"},{"fixed":"80c5b4d6355d1dbece8dd1f812d374f3e24086bc"},{"introduced":"7001c8fdb27357c67147c0a13cb3826e48c0f2bf"},{"fixed":"af74f7db384ed149fe42b21dbd7975f8a54ef227"}],"database_specific":{"cpe":["cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:19.11:*:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:19.11:rc1:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:19.11:rc2:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:19.11:rc3:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:19.11:rc4:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc1:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc2:*:*:*:*:*:*","cpe:2.3:a:dpdk:data_plane_development_kit:22.03:rc3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"20.02"},{"fixed":"22.03"},{"introduced":"19.11"},{"last_affected":"19.11"},{"introduced":"19.11-rc1"},{"last_affected":"19.11-rc1"},{"introduced":"19.11-rc2"},{"last_affected":"19.11-rc2"},{"introduced":"19.11-rc3"},{"last_affected":"19.11-rc3"},{"introduced":"19.11-rc4"},{"last_affected":"19.11-rc4"},{"introduced":"22.03-rc1"},{"last_affected":"22.03-rc1"},{"introduced":"22.03-rc2"},{"last_affected":"22.03-rc2"},{"introduced":"22.03-rc3"},{"last_affected":"22.03-rc3"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["19.11","19.11-rc1","19.11-rc2","19.11-rc3","19.11-rc4","22.03-rc1","22.03-rc2","22.03-rc3","v22.03-rc4","v22.03-rc3","v22.03-rc2","v21.11","v22.03-rc1","v21.11-rc4","v21.11-rc3","v21.11-rc2","v21.11-rc1","v21.08","v21.08-rc4","v21.08-rc3","v21.08-rc2","v21.08-rc1","v21.05","v21.05-rc4","v21.05-rc3","v21.05-rc2","v21.05-rc1","v21.02","v21.02-rc4","v21.02-rc3","v20.11","v21.02-rc2","v21.02-rc1","v20.11-rc5","v20.11-rc4","v20.11-rc3","v20.11-rc2","v20.11-rc1","v20.08","v20.08-rc4","v20.08-rc3","v20.08-rc2","v20.08-rc1","v20.05","v20.05-rc4","v20.05-rc3","v20.05-rc2","v20.05-rc1","v20.02"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-0669.json","vanir_signatures_modified":"2026-07-15T00:26:34Z","vanir_signatures":[{"id":"CVE-2022-0669-46915754","signature_type":"Function","signature_version":"v1","source":"https://github.com/dpdk/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227","target":{"file":"lib/vhost/vhost_user.c","function":"vhost_user_get_inflight_fd"},"deprecated":false,"digest":{"function_hash":"200223244212454310946426545990164687955","length":2695}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/dpdk/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227","target":{"file":"lib/vhost/vhost_user.c"},"deprecated":false,"digest":{"line_hashes":["223818872768659713837531296929638434056","116344875714567526600993095709210440032","65632164188427022346067638745330342493","86925578931592434140037146067078323283","177619426305843807217480219997070703598","329277146593023733927617528617310912643"],"threshold":0.9},"id":"CVE-2022-0669-7cd925aa"},{"target":{"function":"vhost_user_set_inflight_fd","file":"lib/vhost/vhost_user.c"},"deprecated":false,"digest":{"function_hash":"134267928438538481519605856791737735835","length":2619},"id":"CVE-2022-0669-d41ea11d","signature_type":"Function","signature_version":"v1","source":"https://github.com/dpdk/dpdk/commit/af74f7db384ed149fe42b21dbd7975f8a54ef227"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/openvswitch/ovs","events":[{"introduced":"71d553b995d0bd527d3ab1e9fbaf5a2ae34de2f3"},{"last_affected":"8dc1733eaea866dce033b3c44853e1b09bf59fc7"}],"database_specific":{"cpe":["cpe:2.3:a:openvswitch:openvswitch:2.13.0:*:*:*:*:*:*:*","cpe:2.3:a:openvswitch:openvswitch:2.15.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.13.0"},{"last_affected":"2.13.0"},{"introduced":"2.15.0"},{"last_affected":"2.15.0"}],"source":"CPE_STRING"}}],"versions":["2.13.0","2.15.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-0669.json"}}],"schema_version":"1.7.5"}