Data Plane Development Kit
Vendor:
First CVE: Apr 24, 2018 · Active for 8 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Data Plane Development Kit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 24, 2018
8 years ago
Most Recent CVE
Aug 31, 2022
1,423 days ago
CVE Severity & Scoring
Data Plane Development Kit15 CVEs
40%
53%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local10 (66.7%)
Network4 (26.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low12 (80.0%)
High3 (20.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (46.7%)
High4 (26.7%)
None4 (26.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-14374HIGH A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a vir | Sep 30, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-14818HIGH A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with ac | Nov 14, 2019 | 7.5 | 25 | NO | NO |
CVE-2021-3839HIGH A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory rea | Aug 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-10722MEDIUM A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested | May 19, 2020 | 6.7 | 23 | NO | NO |
CVE-2022-2132HIGH A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | Aug 31, 2022 | 8.6 | 22 | NO | NO |
CVE-2022-0669MEDIUM A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFL | Aug 29, 2022 | 6.5 | 21 | NO | NO |
CVE-2018-1059MEDIUM The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual | Apr 24, 2018 | 6.1 | 21 | NO | NO |
CVE-2020-14376HIGH A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a larg | Sep 30, 2020 | 7.8 | 20 | NO | NO |
CVE-2020-10725HIGH A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could | May 20, 2020 | 7.7 | 20 | NO | NO |
CVE-2020-14375HIGH A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the v | Sep 30, 2020 | 7.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Data Plane Development Kit
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 22.03 | 2 | 7.0 | 0.8% | 0 | 0 |
| 19.11 | 1 | 6.5 | 0.3% | 0 | 0 |