CVE-2020-10722 is an integer overflow vulnerability in DPDK versions 18.05 and above, specifically within the vhost_user_set_log_base() function, which can lead to memory corruption due to a smaller-than-requested memory map. This vulnerability primarily affects products from Canonical, DPDK, Fedora Project, OpenSUSE, and Oracle. With a CVSS score of 6.7 (Medium), it requires high privileges for exploitation (PR:H) but has low attack complexity (AC:L), potentially leading to high impact on confidentiality, integrity, and availability (C:H, I:H, A:H). There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 18.05CPE matchmatch criteria | cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
19.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* | ||
20.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
May 18, 2020A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
May 12, 2020