Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10725

Опубликовано: 18 мая 2020
Источник: redhat
CVSS3: 7.7

Описание

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function virtio_dev_rx_batch_packed().

Отчет

The versions of dpdk as shipped with Red Hat Enterprise Linux 7 were not affected by this flaw, as they did not include the vulnerable code, which was introduced in a later version of the package. This issue did not affect the versions of ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for dpdk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Fast Datapath for RHEL 7openvswitchNot affected
Fast Datapath for RHEL 7openvswitch2.10Not affected
Fast Datapath for RHEL 7openvswitch2.11Not affected
Fast Datapath for RHEL 7openvswitch2.12Not affected
Fast Datapath for RHEL 7openvswitch2.13Not affected
Fast Datapath for RHEL 8openvswitch2.11Not affected
Fast Datapath for RHEL 8openvswitch2.12Not affected
Red Hat Ceph Storage 3cephNot affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 7dpdkNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1828894dpdk: librte_vhost Malicious guest could cause segfault by sending invalid Virtio descriptor

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
nvd
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
debian
больше 5 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicio ...

CVSS3: 7.7
github
больше 3 лет назад

A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.

CVSS3: 7.7
fstec
больше 5 лет назад

Уязвимость функции virtio_dev_rx_batch_packed набора библиотек и драйверов для быстрой обработки пакетов dpdk, позволяющая нарушителю вызвать отказ в обслуживании

7.7 High

CVSS3