Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10723

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 6.7

Описание

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

Отчет

This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for DPDK.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitch2.10Will not fix
Fast Datapath for RHEL 7openvswitch2.12Will not fix
Fast Datapath for RHEL 7openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.12Will not fix
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat OpenStack Platform 10 (Newton)openvswitchOut of support scope
Red Hat OpenStack Platform 13 (Queens)openvswitchAffected
Red Hat OpenStack Platform 15 (Stein)rhosp-openvswitchNot affected
Red Hat OpenStack Platform 16 (Train)rhosp-openvswitchNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1828874dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 5 лет назад

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

CVSS3: 5.1
nvd
больше 5 лет назад

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

CVSS3: 5.1
msrc
5 месяцев назад

A memory corruption issue was found in DPDK versions 17.05 and above

CVSS3: 5.1
debian
больше 5 лет назад

A memory corruption issue was found in DPDK versions 17.05 and above. ...

CVSS3: 6.7
github
больше 3 лет назад

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

6.7 Medium

CVSS3