Input validation error in DPDK - CVE-2020-10722

 

Input validation error in DPDK - CVE-2020-10722

Published: May 19, 2020 / Updated: May 26, 2020


Vulnerability identifier: #VU27994
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10722
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in check log functionality. A remote attacker can pass specially crafted input to the application, trigger mmap offset and perform a denial of service (DoS) attack.


Affected software

DPDK
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
ovn2.11 (Red Hat package)
openvswitch (Alpine package)
openvswitch2.12 (Red Hat package)
dpdk (Debian package)
dpdk (Ubuntu package)
ovirt-ansible-repositories (Red Hat package)
python-ovirt-engine-sdk4 (Red Hat package)
dpdk (Red Hat package)
dpdk
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization
Red Hat Virtualization Host
Red Hat Virtualization Manager
Red Hat Enterprise Linux Fast Datapath
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Opensuse
Fedora
Oracle Communications Session Border Controller

How to mitigate CVE-2020-10722

Install updates from vendor's website.

DPDK - addressed in versions 19.11.2, 20.02.1
openvswitch (Red Hat package) - addressed in versions 2.9.0-130.el7fdp, 2.13.0-25.el8fdp.1
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.0-54.20200327gita4efc59.el7fdp, 2.11.0-54.20200327gita4efc59.el8fdp
ovn2.11 (Red Hat package) - update to 2.11.1-44.el7fdp
openvswitch (Alpine package) - update to 2.12.2-r0
dpdk (Debian package) - addressed in versions 16.11.11-1+deb9u2, 18.11.6-1~deb10u2, 19.11.2-1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
ovirt-ansible-repositories (Red Hat package) - update to 1.1.6-1.el7ev
python-ovirt-engine-sdk4 (Red Hat package) - update to 4.3.4-1.el7ev
dpdk (Red Hat package) - addressed in versions 18.11.8-1.el7_8, 19.11.3-1.el8
dpdk - update to 19.11.1-2.fc32

External References

Related Security Bulletins