CVE-2020-14377: High severity dpdk (data plane development kit) vulnerability
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual machine to read significant amounts of host memory. The highest threat from this vulnerability is to data confidentiality and system availability.
Other sources
Complete lack of validation of attacker-controlled parameters leads to a buffer over read. The results of the over read are written back to the guest virtual machine=E2=80=99s memory. This vulnerability can be used by an attacker in a virtual machine to read significant amounts of host memory. This vulnerability can be chained with finding number 1 to read arbitrary amounts of data from any address in the vhostcrypto process.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw in dpdk?
The vulnerability ID for this flaw in dpdk is CVE-2020-14377.
What is the severity of CVE-2020-14377?
The severity of CVE-2020-14377 is high with a CVSS score of 7.1.
How does CVE-2020-14377 impact dpdk?
CVE-2020-14377 can lead to a buffer over read in dpdk, allowing an attacker to write data back to the guest virtual machine memory.
Which versions of dpdk are affected by CVE-2020-14377?
Versions before 18.11.10 and before 19.11.5 of dpdk are affected by CVE-2020-14377.
How can I fix the vulnerability CVE-2020-14377?
To fix the vulnerability CVE-2020-14377, update dpdk to version 18.11.10 or 19.11.5, or later.