Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-14375
Linux Debian vulnerability analysis and mitigation

Overview

A high-severity vulnerability (CVE-2020-14375) was discovered in DPDK (Data Plane Development Kit) versions before 18.11.10 and before 19.11.5. The vulnerability involves time-of-check time-of-use issues throughout vhost_crypto.c, where virtio ring descriptors and their associated data are accessible from both virtual machine and host environments (DPDK Advisory, NVD).

Technical details

The vulnerability stems from vhost_crypto.c's direct access to descriptors in shared memory regions, which is inherently unsafe. The issue has a CVSS score of 7.8 (High) with the following vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H. The technical root cause involves the way vhost_crypto validates and processes data in shared memory regions, where an attacker can modify the contents after validation (DPDK Advisory).

Impact

The vulnerability can lead to multiple severe consequences including data confidentiality and integrity breaches, as well as system availability impacts. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it, potentially leading to unauthorized access to host system resources (NVD, DPDK Advisory).

Exploitability

The vulnerability requires local access with low privileges but high attack complexity. It can be exploited by an attacker within a virtual machine environment to potentially compromise the host system. The vulnerability has been confirmed to be exploitable in laboratory conditions (DPDK Advisory).

Mitigation and workarounds

The vulnerability has been fixed in DPDK versions 18.11.10 and 19.11.5. Users are strongly encouraged to upgrade to these or later versions. For Red Hat Enterprise Linux 7 and 8, the vulnerability does not affect their shipped versions as they do not enable generic crypto device library support (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80274HIGH7.5
  • Linux Debian logoLinux Debian
  • bind9
NoNoSep 16, 2026
CVE-2026-76163HIGH7.5
  • Linux Debian logoLinux Debian
  • bind9
NoNoSep 16, 2026
CVE-2026-42784HIGH7.4
  • Linux Debian logoLinux Debian
  • rust-sequoia-openpgp+crypto-nettle-devel
NoYesSep 16, 2026
CVE-2026-77119MEDIUM5.9
  • Linux Debian logoLinux Debian
  • bind9.16-utils
NoNoSep 16, 2026
CVE-2026-75029MEDIUM5.3
  • Linux Debian logoLinux Debian
  • bind9
NoNoSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management