CVE-2020-14376
Linux Debian vulnerability analysis and mitigation

Overview

A buffer overflow vulnerability (CVE-2020-14376) was discovered in DPDK (Data Plane Development Kit) versions before 18.11.10 and before 19.11.5. The vulnerability stems from a lack of bounds checking when copying iv_data from VM guest memory into host memory, which can lead to a large buffer overflow. This vulnerability was reported by Ryan Hall and was disclosed on September 28, 2020 (DPDK Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H. The issue specifically occurs in the vhost crypto functionality when copying iv_data from guest to host in the prepare_sym_cipher_op and prepare_sym_chain_op operations. The vulnerability is classified as CWE-120 (Buffer Copy without Checking Size of Input) (NVD).

Impact

The vulnerability poses a significant threat to data confidentiality and integrity as well as system availability. The size and location of this overflow gives the attacker extensive control and could potentially lead to remote code execution. A malicious guest can exploit this vulnerability to harm the host using vhost crypto, potentially leading to information disclosure and system compromise (Bugzilla).

Exploitability

The vulnerability requires local access with low privileges and high attack complexity to exploit. It affects the vhost crypto functionality, which must be enabled for the vulnerability to be exploitable. Some systems, such as Red Hat Enterprise Linux 7 and 8, are not affected as they do not enable generic crypto device library support (Bugzilla).

Mitigation and workarounds

The vulnerability has been fixed in DPDK versions 18.11.10 and 19.11.5. All users of the vhost library are strongly encouraged to upgrade to these versions or later. For Ubuntu 20.04 LTS, the fix is available in version 19.11.3-0ubuntu0.2 (Ubuntu Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87733MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoYesSep 09, 2026
CVE-2026-87732MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoYesSep 09, 2026
CVE-2026-87737MEDIUM5.9
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoYesSep 09, 2026
CVE-2026-87736MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoYesSep 09, 2026
CVE-2026-87735MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoYesSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management