6.9
CVSSv2

CVE-2020-14376

Published: 30/09/2020 Updated: 05/01/2021
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7.8 | Impact Score: 6 | Exploitability Score: 1.1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

A flaw was found in dpdk in versions prior to 18.11.10 and prior to 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dpdk data plane development kit

opensuse leap 15.1

canonical ubuntu linux 20.04

opensuse leap 15.2

Vendor Advisories

Debian Bug report logs - #971269 dpdk: CVEs for multiple vhost crypto issues Package: src:dpdk; Maintainer for src:dpdk is Debian DPDK Maintainers <pkg-dpdk-devel@listsaliothdebianorg>; Reported by: Luca Boccassi <bluca@debianorg> Date: Mon, 28 Sep 2020 15:45:02 UTC Severity: important Tags: security Found in ve ...

Mailing Lists

Hello, Is there any particular reason for the Scope metric to be Unchanged (S:U) for CVE-2020-14377 and CVE-2020-14378? Thank you, On Mon, Sep 28, 2020 at 5:43 PM Ferruh Yigit <ferruhyigit () intel com> wrote: -- Mauro Matteo Cascella Red Hat Product Security PGP-Key ID: BB3410B0 ...
On 1/4/2021 8:28 AM, Mauro Matteo Cascella wrote: removed dpdk-announce mail list Hi Mauro, Is there a concern on the selected scope metric? Thanks ...
A set of vulnerabilities are fixed in DPDK: - CVE-2020-14374 - CVE-2020-14375 - CVE-2020-14376 - CVE-2020-14377 - CVE-2020-14378 Some downstream stakeholders were warned in advance in order to coordinate the release of fixes and reduce the vulnerability window Problem: A malicious guest can harm the host using vhost crypto, this includes executi ...
On Mon, Jan 4, 2021 at 12:29 PM Ferruh Yigit <ferruhyigit () intel com> wrote: Thank you for the timely reply With regard to CVE-2020-14377, the Scope metric was rated differently by NIST [1] hence my initial question [1] nvdnistgov/vuln/detail/CVE-2020-14377 kind of guest-to-host compromise, which usually implies a Scope ...