CVE-2020-10725: High severity DPDK Data Plane Development Kit vulnerability
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtiodevrxbatchpacked().
Other sources
A vulnerability was found in DPDK through version 19.11, virtiodevrxbatchpacked() misses checking whether the descriptor address is valid. A Malicious guest could cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10725?
CVE-2020-10725 is a vulnerability found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, resulting in a loss of connectivity for other guests on the host.
How severe is CVE-2020-10725?
CVE-2020-10725 has a severity rating of 7.7 (High).
Which software versions are affected by CVE-2020-10725?
DPDK version 19.11 and above are affected by CVE-2020-10725.
How can I fix the CVE-2020-10725 vulnerability?
To fix the CVE-2020-10725 vulnerability, update DPDK to version 20.02.1 or apply the recommended patches provided by Red Hat.
Where can I find more information about CVE-2020-10725?
You can find more information about CVE-2020-10725 at the following references: [link1], [link2], [link3].