Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dpdk

First CVE: Jan 23, 2018Active for: 8 yearsTotal CVEs: 16
34.9
VTI Score
Medium

DPDK is a modestly represented framework for software-defined packet processing widely embedded in telecommunications, cloud infrastructure, and high-performance networking environments. Its vulnerability profile concentrates in the core Data Plane Development Kit and recurs through memory-safety and initialization weaknesses—integer overflows, out-of-bounds reads, buffer overflows, and sensitive-data exposure—that are characteristic of performance-critical, low-level packet-handling code. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dpdk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2018
8 years ago
Most Recent CVE
Aug 31, 2022
1,423 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-14374HIGH
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a vir
Sep 30, 20208.827NONO
CVE-2015-1142857HIGH
On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079
Jan 23, 20188.626NONO
CVE-2019-14818HIGH
A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with ac
Nov 14, 20197.525NONO
CVE-2021-3839HIGH
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory rea
Aug 23, 20227.524NONO
CVE-2020-10722MEDIUM
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested
May 19, 20206.723NONO
CVE-2022-2132HIGH
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
Aug 31, 20228.622NONO
CVE-2022-0669MEDIUM
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFL
Aug 29, 20226.521NONO
CVE-2018-1059MEDIUM
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual
Apr 24, 20186.121NONO
CVE-2020-14376HIGH
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a larg
Sep 30, 20207.820NONO
CVE-2020-10725HIGH
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could
May 20, 20207.720NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
38%
56%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local10 (62.5%)
Network5 (31.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.3%)
Attack Complexity
Low13 (81.3%)
High3 (18.8%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (43.8%)
High4 (25.0%)
None5 (31.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dpdk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dpdk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dpdk's Products

View all 2 CNAs →

Top CWEs