CVE-2020-14376: Buffer Overflow
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying ivdata from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
Lack of bounds checking when copying ivdata from the VM guest memory into host memory can lead to a large buffer overflow. The size and location of this overflow gives the attacker extensive control and could potentially lead to remote code execution.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in dpdk?
The vulnerability ID for this flaw in dpdk is CVE-2020-14376.
What is the severity of CVE-2020-14376?
The severity of CVE-2020-14376 is rated as high with a severity value of 7.8.
What is the highest threat from CVE-2020-14376?
The highest threat from CVE-2020-14376 is to data confidentiality and integrity, as well as system.
Which versions of dpdk are affected by CVE-2020-14376?
Versions before 18.11.10 and before 19.11.5 of dpdk are affected by CVE-2020-14376.
How can I fix CVE-2020-14376?
To fix CVE-2020-14376, update dpdk to version 18.11.10 or 19.11.5 or later.