Vulnerability Details CVE-2020-14378
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.8%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 2.1
Products affected by CVE-2020-14378
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.02.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.3
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.4
-
cpe:2.3:a:dpdk:data_plane_development_kit:18.11.5
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.02
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.05
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08.1
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.08.2
-
cpe:2.3:a:dpdk:data_plane_development_kit:19.11
-
cpe:2.3:o:canonical:ubuntu_linux:20.04
-
cpe:2.3:o:opensuse:leap:15.1
-
cpe:2.3:o:opensuse:leap:15.2