3.6
CVSSv2

CVE-2020-14377

Published: 30/09/2020 Updated: 05/01/2021
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

A flaw was found in dpdk in versions prior to 18.11.10 and prior to 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual machine to read significant amounts of host memory. The highest threat from this vulnerability is to data confidentiality and system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dpdk data plane development kit

canonical ubuntu linux 20.04

opensuse leap 15.1

opensuse leap 15.2

Vendor Advisories

Debian Bug report logs - #971269 dpdk: CVEs for multiple vhost crypto issues Package: src:dpdk; Maintainer for src:dpdk is Debian DPDK Maintainers <pkg-dpdk-devel@listsaliothdebianorg>; Reported by: Luca Boccassi <bluca@debianorg> Date: Mon, 28 Sep 2020 15:45:02 UTC Severity: important Tags: security Found in ve ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: DPDK security advisory for multiple vhost crypto issues <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Mauro ...
<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: [dpdk-dev] [oss-security] DPDK security advisory for multiple vhost crypto issues <!--X-Subject-Header-End--> <!--X-Head-o ...