First published: Tue Apr 28 2020(Updated: )
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openvswitch2.11 | <0:2.11.0-54.20200327gita4efc59.el7fd | 0:2.11.0-54.20200327gita4efc59.el7fd |
redhat/openvswitch | <0:2.9.0-130.el7fd | 0:2.9.0-130.el7fd |
redhat/openvswitch2.13 | <0:2.13.0-25.el8fd | 0:2.13.0-25.el8fd |
redhat/openvswitch2.11 | <0:2.11.0-54.20200327gita4efc59.el8fd | 0:2.11.0-54.20200327gita4efc59.el8fd |
redhat/dpdk | <0:18.11.8-1.el7_8 | 0:18.11.8-1.el7_8 |
redhat/dpdk | <0:19.11.3-1.el8 | 0:19.11.3-1.el8 |
redhat/openvswitch2.11 | <0:2.11.3-77.el7fd | 0:2.11.3-77.el7fd |
redhat/openvswitch-selinux-extra-policy | <0:1.0-17.el7fd | 0:1.0-17.el7fd |
redhat/ovn2.11 | <0:2.11.1-57.el7fd | 0:2.11.1-57.el7fd |
redhat/ovn2.11 | <0:2.11.1-44.el7fd | 0:2.11.1-44.el7fd |
Dpdk Data Plane Development Kit | <=17.05 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.10 | |
Canonical Ubuntu Linux | =20.04 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
Oracle Communications Session Border Controller | >=8.2<=8.4 | |
Oracle Enterprise Communications Broker | =3.1.0 | |
Oracle Enterprise Communications Broker | =3.2.0 | |
ubuntu/dpdk | <17.11.9-0ubuntu18.04.2 | 17.11.9-0ubuntu18.04.2 |
ubuntu/dpdk | <18.11.5-0ubuntu0.19.10.2 | 18.11.5-0ubuntu0.19.10.2 |
ubuntu/dpdk | <19.11.1-0ubuntu1.1 | 19.11.1-0ubuntu1.1 |
ubuntu/dpdk | <19.11.2<18.11.8<20.02.1 | 19.11.2 18.11.8 20.02.1 |
redhat/dpdk | <20.02.1 | 20.02.1 |
redhat/dpdk | <19.11.2 | 19.11.2 |
redhat/dkdk | <18.11.8 | 18.11.8 |
debian/dpdk | 18.11.11-1~deb10u1 18.11.11-1~deb10u2 20.11.10-1~deb11u1 20.11.6-1~deb11u1 22.11.4-1~deb12u1 23.11-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-10723 is a memory corruption issue found in DPDK versions 17.05 and above.
The memory corruption issue in CVE-2020-10723 is caused by an integer truncation on the index of a payload.
DPDK versions 17.05 and above are affected by CVE-2020-10723.
CVE-2020-10723 has a severity rating of 6.7, which is considered medium.
To fix CVE-2020-10723, update DPDK to version 20.02.1 or higher.