CVE-2020-14376 describes a buffer overflow vulnerability in DPDK versions prior to 18.11.10 and 19.11.5, stemming from a lack of bounds checking during iv_data copying from VM guest to host memory. This flaw impacts various Canonical, DPDK, and OpenSUSE products. Rated as High severity (CVSS 7.8), it presents a significant risk to data confidentiality, integrity, and system availability, with a local attack vector and high attack complexity. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.02.1, < 18.11.10CPE matchmatch criteria | cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:* | ||
>= 19.02, < 19.11.5CPE matchmatch criteria | cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:* | ||
20.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
dpdk: buffer overflow copying iv_data from guest to host (prepare_sym_cipher_op & prepare_sym_chain_op)
Sep 28, 2020A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Sep 8, 2020