Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10725

Опубликовано: 20 мая 2020
Источник: nvd
CVSS3: 7.7
CVSS2: 4
EPSS Низкий

Описание

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtio_dev_rx_batch_packed().

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dpdk:data_plane_development_kit:*:*:*:*:*:*:*:*
Версия до 19.11 (включая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Конфигурация 4

Одно из

cpe:2.3:a:oracle:enterprise_communications_broker:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00606
Низкий

7.7 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-665
CWE-665

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
redhat
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
debian
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicio ...

CVSS3: 7.7
github
больше 3 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость функции virtio_dev_rx_batch_packed набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.00606
Низкий

7.7 High

CVSS3

4 Medium

CVSS2

Дефекты

CWE-665
CWE-665