Vulnerability identifier: #VU47312
Vulnerability risk: Medium
CVSSv4.0: 4.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-14378
CWE-ID:
CWE-190
Exploitation vector: Local network
Exploit availability: No
Vulnerable software:
DPDK
Server applications /
Frameworks for developing and running applications
Vendor: DPDK Project
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in the move_desc() function. A remote user on the guest OS can consume large amounts of CPU cycles and prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
DPDK: 18.02 - 18.11.9, 19.02 - 19.11.4
External links
https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00004.html
https://lists.opensuse.org/opensuse-security-announce/2020-10/msg00006.html
https://bugzilla.redhat.com/show_bug.cgi?id=1879473
https://usn.ubuntu.com/4550-1/
https://www.openwall.com/lists/oss-security/2020/09/28/3
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.