Vulnerability Details CVE-2020-10725
A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_rx_batch_packed()`.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.5%
CVSS Severity
CVSS v3 Score 7.7
CVSS v2 Score 4.0
Products affected by CVE-2020-10725
-
cpe:2.3:a:dpdk:data_plane_development_kit:-
-
cpe:2.3:a:dpdk:data_plane_development_kit:1.7.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:1.8.0
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.04
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.07.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.10
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.6
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.7
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.8
-
cpe:2.3:a:dpdk:data_plane_development_kit:16.11.9
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.02.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.05.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.08.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.6
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.7
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.8
-
cpe:2.3:a:dpdk:data_plane_development_kit:17.11.9
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.10
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.15.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:2.0.0
-
cpe:2.3:a:dpdk:data_plane_development_kit:2.1.0
-
cpe:2.3:a:dpdk:data_plane_development_kit:2.2.0
-
cpe:2.3:a:oracle:enterprise_communications_broker:3.1.0
-
cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0
-
cpe:2.3:o:fedoraproject:fedora:32
-
cpe:2.3:o:opensuse:leap:15.1