DPDK is a modestly represented framework for software-defined packet processing widely embedded in telecommunications, cloud infrastructure, and high-performance networking environments. Its vulnerability profile concentrates in the core Data Plane Development Kit and recurs through memory-safety and initialization weaknesses—integer overflows, out-of-bounds reads, buffer overflows, and sensitive-data exposure—that are characteristic of performance-critical, low-level packet-handling code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dpdk over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14374HIGH A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a vir | Sep 30, 2020 | 8.8 | 27 | NO | NO |
CVE-2015-1142857HIGH On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079 | Jan 23, 2018 | 8.6 | 26 | NO | NO |
CVE-2019-14818HIGH A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with ac | Nov 14, 2019 | 7.5 | 25 | NO | NO |
CVE-2021-3839HIGH A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory rea | Aug 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-10722MEDIUM A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested | May 19, 2020 | 6.7 | 23 | NO | NO |
CVE-2022-2132HIGH A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | Aug 31, 2022 | 8.6 | 22 | NO | NO |
CVE-2022-0669MEDIUM A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFL | Aug 29, 2022 | 6.5 | 21 | NO | NO |
CVE-2018-1059MEDIUM The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual | Apr 24, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-14376HIGH A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a larg | Sep 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-10725HIGH A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could | May 20, 2020 | 7.7 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dpdk.
Media articles that mention a CVE ID that affects a product developed by Dpdk — matched by CVE ID, not by vendor name.