ZeroHour

CVE-2020-14378

CVSS 3.1
3.3 low
EPSS
<1%p33
Published
()
Modified
Description

An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.

Vendors
dpdkcanonicalopensuse
Products
data plane development kit, ubuntu linux, leap
Weakness
CWE-191
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.