Cryptographic issues in DPDK - CVE-2020-10724

 

Cryptographic issues in DPDK - CVE-2020-10724

Published: May 19, 2020 / Updated: May 26, 2020


Vulnerability identifier: #VU27997
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10724
CWE-ID: CWE-310
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to incorrect validation of keys lengths. A remote attacker can bypass certain security restrictions.


Affected software

DPDK
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch (Alpine package)
openvswitch2.12 (Red Hat package)
dpdk (Debian package)
dpdk (Ubuntu package)
dpdk
Opensuse
Fedora

How to mitigate CVE-2020-10724

Install updates from vendor's website.

DPDK - addressed in versions 19.11.2, 20.02.1
openvswitch (Red Hat package) - update to 2.13.0-25.el8fdp.1
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.0-54.20200327gita4efc59.el7fdp, 2.11.0-54.20200327gita4efc59.el8fdp
openvswitch (Alpine package) - update to 2.12.2-r0
dpdk (Debian package) - addressed in versions 16.11.11-1+deb9u2, 18.11.6-1~deb10u2, 19.11.2-1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
dpdk - update to 19.11.1-2.fc32

External References

Related Security Bulletins