
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity vulnerability (CVE-2020-14375) was discovered in DPDK (Data Plane Development Kit) versions before 18.11.10 and before 19.11.5. The vulnerability involves time-of-check time-of-use issues throughout vhost_crypto.c, where virtio ring descriptors and their associated data are accessible from both virtual machine and host environments (DPDK Advisory, NVD).
The vulnerability stems from vhost_crypto.c's direct access to descriptors in shared memory regions, which is inherently unsafe. The issue has a CVSS score of 7.8 (High) with the following vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H. The technical root cause involves the way vhost_crypto validates and processes data in shared memory regions, where an attacker can modify the contents after validation (DPDK Advisory).
The vulnerability can lead to multiple severe consequences including data confidentiality and integrity breaches, as well as system availability impacts. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it, potentially leading to unauthorized access to host system resources (NVD, DPDK Advisory).
The vulnerability requires local access with low privileges but high attack complexity. It can be exploited by an attacker within a virtual machine environment to potentially compromise the host system. The vulnerability has been confirmed to be exploitable in laboratory conditions (DPDK Advisory).
The vulnerability has been fixed in DPDK versions 18.11.10 and 19.11.5. Users are strongly encouraged to upgrade to these or later versions. For Red Hat Enterprise Linux 7 and 8, the vulnerability does not affect their shipped versions as they do not enable generic crypto device library support (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."