CVE-2020-10725

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:a:oracle:enterprise_communications_broker:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*

Information

Published : 2020-05-20 07:15

Updated : 2022-09-02 08:36


NVD link : CVE-2020-10725

Mitre link : CVE-2020-10725


JSON object : View

CWE
CWE-665

Improper Initialization

Advertisement

dedicated server usa

Products Affected

oracle

  • enterprise_communications_broker

dpdk

  • data_plane_development_kit

fedoraproject

  • fedora

opensuse

  • leap