
Cloud Vulnerability DB
A community-led vulnerabilities database
A buffer overflow vulnerability (CVE-2020-14376) was discovered in DPDK (Data Plane Development Kit) versions before 18.11.10 and before 19.11.5. The vulnerability stems from a lack of bounds checking when copying iv_data from VM guest memory into host memory, which can lead to a large buffer overflow. This vulnerability was reported by Ryan Hall and was disclosed on September 28, 2020 (DPDK Advisory).
The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (High) with the vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H. The issue specifically occurs in the vhost crypto functionality when copying iv_data from guest to host in the prepare_sym_cipher_op and prepare_sym_chain_op operations. The vulnerability is classified as CWE-120 (Buffer Copy without Checking Size of Input) (NVD).
The vulnerability poses a significant threat to data confidentiality and integrity as well as system availability. The size and location of this overflow gives the attacker extensive control and could potentially lead to remote code execution. A malicious guest can exploit this vulnerability to harm the host using vhost crypto, potentially leading to information disclosure and system compromise (Bugzilla).
The vulnerability requires local access with low privileges and high attack complexity to exploit. It affects the vhost crypto functionality, which must be enabled for the vulnerability to be exploitable. Some systems, such as Red Hat Enterprise Linux 7 and 8, are not affected as they do not enable generic crypto device library support (Bugzilla).
The vulnerability has been fixed in DPDK versions 18.11.10 and 19.11.5. All users of the vhost library are strongly encouraged to upgrade to these versions or later. For Ubuntu 20.04 LTS, the fix is available in version 19.11.3-0ubuntu0.2 (Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."