Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-28199

28
FAUCET Score

CVE-2022-28199 is a high-severity vulnerability in NVIDIA's Data Plane Development Kit (MLNX_DPDK) network stack, stemming from improper error recovery. This flaw primarily affects NVIDIA, Linux, and Microsoft distributions of DPDK, as well as the Linux kernel and Windows operating systems. With a CVSS score of 8.6, it can be exploited remotely without authentication, potentially leading to denial of service and some impact on data integrity and confidentiality. While there are no known public exploits or Metasploit modules, the vulnerability has garnered minimal community discussion and limited media coverage, with no indication of active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 19.11_1.0.0, < 20.11_5.0.0CPE matchmatch criteria
cpe:2.3:a:nvidia:data_plane_development_kit:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.88%
Probability of exploitation in next 30 days
EPSS Percentile
77.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0188 is in the 60th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 8Fixed in: openvswitch2.13-0:2.13.0-193.3.el8fdp
View patch
redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 8Fixed in: openvswitch2.17-0:2.17.0-37.4.el8fdp
View patch
redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 8Fixed in: openvswitch2.15-0:2.15.0-113.3.el8fdp
View patch
redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 8Fixed in: openvswitch2.16-0:2.16.0-89.3.el8fdp
View patch
redhatpatch availablevia redhat_api
Product: Fast Datapath for Red Hat Enterprise Linux 9Fixed in: openvswitch2.17-0:2.17.0-32.4.el9fdp
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: dpdk-2:21.11.2-1.el9_1
View patch
redhatend of lifevia redhat_api
Product: Fast Datapath for RHEL 7Fixed in: dpdk
redhatend of lifevia redhat_api
Product: Fast Datapath for RHEL 7Fixed in: openvswitch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dpdk
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openvswitch2.15
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openvswitch2.16
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openvswitch2.17

Vendor Advisories (1)

redhatCVE-2022-28199Moderate

dpdk: error recovery in mlx5 driver not handled properly, allowing for denial of service

Aug 30, 2022

References

nvidia.custhelp.com / app/answers/detail/a_id/5389
Vendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-mlx5-jbPCrqD8
openwall.com / lists/oss-security/2022/09/06/2
Mailing ListThird Party Advisory