CVE-2022-28199

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
01/09/2022
Last modified:
07/09/2022

Description

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:data_plane_development_kit:*:*:*:*:*:*:*:* 19.11_1.0.0 (including) 20.11_5.0.0 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*