Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14378
HistorySep 29, 2020 - 2:40 p.m.

CVE-2020-14378

2020-09-2914:40:41
redhat.com
access.redhat.com
9

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

0.0005 Low

EPSS

Percentile

17.4%

An integer underflow flaw was found in the move_desc function that can lead to large amounts of CPU cycles being consumed in a long-running loop. This flaw allows an attacker to cause move_desc to get stuck in a 4,294,967,295-count iteration loop. Depending on how vhost_crypto is being used, this issue could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period. The highest threat from this vulnerability is to system availability.

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

3.3 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

0.0005 Low

EPSS

Percentile

17.4%