Lucene search

K
cve[email protected]CVE-2020-14378
HistorySep 30, 2020 - 7:15 p.m.

CVE-2020-14378

2020-09-3019:15:12
CWE-191
web.nvd.nist.gov
118
cve-2020-14378
integer underflow
dpdk
cpu consumption
vulnerability
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

5.7 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.4%

An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the move_desc function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause move_desc to get stuck in a 4,294,967,295-count iteration loop. Depending on how vhost_crypto is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.

Affected configurations

Vulners
NVD
Node
dpdkdpdkRange18.11.10
OR
dpdkdpdkRange19.11.5
VendorProductVersionCPE
dpdkdpdk*cpe:2.3:o:dpdk:dpdk:*:*:*:*:*:*:*:*
dpdkdpdk*cpe:2.3:o:dpdk:dpdk:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "dpdk",
    "versions": [
      {
        "version": "All dpdk versions before 18.11.10 and before 19.11.5",
        "status": "affected"
      }
    ]
  }
]

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

5.7 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.4%