Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10724

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

Отчет

This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for DPDK. Red Hat Enterprise Linux 7 and 8 are not affected by this flaw, as vhost-crypto backend is not built and shipped in DPDK packages.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.12Not affected
Fast Datapath for RHEL 7openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.12Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 7dpdkNot affected
Red Hat Enterprise Linux 8dpdkNot affected
Red Hat OpenStack Platform 10 (Newton)openvswitchOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1828884dpdk: librte_vhost Missing inputs validation in Vhost-crypto

EPSS

Процентиль: 24%
0.0008
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 5 лет назад

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

CVSS3: 5.1
nvd
больше 5 лет назад

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

CVSS3: 5.1
msrc
5 месяцев назад

A vulnerability was found in DPDK versions 18.11 and above

CVSS3: 5.1
debian
больше 5 лет назад

A vulnerability was found in DPDK versions 18.11 and above. The vhost- ...

github
больше 3 лет назад

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.

EPSS

Процентиль: 24%
0.0008
Низкий

5.1 Medium

CVSS3