From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id A83C1A04C3 for ; Mon, 28 Sep 2020 17:24:57 +0200 (CEST) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id 934B71DA03; Mon, 28 Sep 2020 17:24:56 +0200 (CEST) Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) by dpdk.org (Postfix) with ESMTP id 787891D557 for ; Mon, 28 Sep 2020 17:22:13 +0200 (CEST) Received: by mail-wr1-f54.google.com with SMTP id k10so1801190wru.6 for ; Mon, 28 Sep 2020 08:22:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=mRmEmqNFLBnon5YwBK7c8rKKel+GJsz39nUDb4pF5H0=; b=MrDbSqeL/LWH6F/mGZfSeEPtL9J6zJwN07Tm+37vnYz3C0WCQr7tpb06Bh/HOdCxSp wLhvcX2Hfb0A8rxQ+cmqFH0vzkLDPsNbzkAMwn7uDeUeUpv0fZ2SffJZGAscWOwX8Mrs Ma4/ylxZ3Wbx4NRj6+li9m9Djz+BvjxmdqYsVveaZjMCNTuOZS6U8G8cIMTRPn7uyy4n FoBgpieCQnozLFi3NtkE9k7JXB1GG7tkjmmwKCZghLw+oKQNGF9oSVW/AlSUWfkNyDwT emF0ycoEzFEP9CfeItv+H6vCaC6jY9d4alyAhR7LxQqVMoIUd9OOqZFCLKn5QIai2vj3 D+qA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:subject:date:message-id:mime-version :content-transfer-encoding; bh=mRmEmqNFLBnon5YwBK7c8rKKel+GJsz39nUDb4pF5H0=; b=uejVvicEof0w6PeBMDjTnkAfujIFJw6d5UKB/e6UtVh2Ebb2c/4/OLL9ikR4GR6BLI A7Mcb1IaeTgQwlPNmcuLDCN+zl6DIgpzRJpo0YnuBO97cFx6qiUxTrthc/DWt1M4EPoc M1zAlGwkTX7CFkm/epjSour2f3IKNgWnuEvRfu1B8k0gTWSs3cDx+hXb5gd1MT5dBbJC gs7OQKNvMVpD7U8EHNmsmHsgNEHxfbYm6jj+FYGjRkW3pfbjjat5VphoCI1e+Ekdp8LS HvHp3YTNBdeWGI0R7PXKCH21UnSuenQXEweXvdq2G5182HWdydVqjRPA7nGZfzdkBV6X /oAw== X-Gm-Message-State: AOAM530vWjAmBoHeDg5EHZNsMvG4/FsLHkqEQZx97y3XzzIaKhu73zEb 7etliH+ImgEPsPTJtHYzUab2fVrulaHNGA== X-Google-Smtp-Source: ABdhPJxTGuX7QLcE2Pnu/wVj8oAKixoofwjjU1z+TOhGgc4H4Vu3bkbYwm6VdiwDwvELEZOKjzJbLw== X-Received: by 2002:adf:e4c9:: with SMTP id v9mr2185099wrm.375.1601306531965; Mon, 28 Sep 2020 08:22:11 -0700 (PDT) Received: from localhost ([88.98.246.218]) by smtp.gmail.com with ESMTPSA id w81sm1699383wmg.47.2020.09.28.08.22.11 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 28 Sep 2020 08:22:11 -0700 (PDT) From: luca.boccassi@gmail.com To: announce@dpdk.org Date: Mon, 28 Sep 2020 16:22:08 +0100 Message-Id: <20200928152208.2857501-1-luca.boccassi@gmail.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Mailman-Approved-At: Mon, 28 Sep 2020 17:24:55 +0200 Subject: [dpdk-announce] DPDK 19.11.5 released X-BeenThere: announce@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: DPDK announcements List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: announce-bounces@dpdk.org Sender: "announce" Hi all, Here is a new stable release: https://fast.dpdk.org/rel/dpdk-19.11.5.tar.xz The git tree is at: https://dpdk.org/browse/dpdk-stable/?h=19.11 This release fixes the following security issues: CVE: CVE-2020-14374 Severity: 8.8 (High) CVSS scores: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Description: dpdk: Remote Code Execution in vhost_crypto (VM Escape) CVE: CVE-2020-14375 Severity: 7.8 (High) CVSS scores: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Description: dpdk: Time-of-check time-of-use vulnerabilities throughout vhost_crypto.c CVE: CVE-2020-14376 Severity: 7.8 (High) CVSS scores: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Description: dpdk: Buffer overflow copying iv_data from guest to host(prepare_sym_cipher_op & prepare_sym_chain_op) CVE: CVE-2020-14377 Severity: 7.1 (High) CVSS scores: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Description: dpdk: write_back_data buffer over read (cipher->para.dst_data_len & de= sc->len) CVE: CVE-2020-14378 Severity: 3.3 (Low) CVSS scores: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Description: dpdk: Partial Denial of Service due to Integer Underflow Validation of the cryptodev changes was performed by the Intel validation team. Thanks to "Ryan Hall " for reporting the issues. Please see https://bugs.dpdk.org/show_bug.cgi?id=272 for more information. Luca Boccassi --- VERSION | 2 +- doc/guides/rel_notes/release_19_11.rst | 22 ++ examples/vhost_crypto/main.c | 2 +- lib/librte_vhost/rte_vhost_crypto.h | 3 + lib/librte_vhost/vhost_crypto.c | 452 ++++++++++++++++++--------------- 5 files changed, 271 insertions(+), 210 deletions(-) Fan Zhang (6): vhost/crypto: fix pool allocation vhost/crypto: fix incorrect descriptor deduction vhost/crypto: fix missed request check for copy mode vhost/crypto: fix incorrect write back source vhost/crypto: fix data length check vhost/crypto: fix possible TOCTOU attack Luca Boccassi (1): version: 19.11.5