Memory leak in DPDK - CVE-2020-10725

 

Memory leak in DPDK - CVE-2020-10725

Published: May 19, 2020 / Updated: May 26, 2020


Vulnerability identifier: #VU27998
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10725
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak. A remote attacker can force the application to leak memory and perform denial of service attack.


Affected software

DPDK
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.12 (Red Hat package)
dpdk (Ubuntu package)
dpdk
dpdk (Red Hat package)
dpdk-devel
dpdk-tools
dpdk-doc
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - TUS
Opensuse
Fedora

How to mitigate CVE-2020-10725

Install updates from vendor's website.

DPDK - addressed in versions 19.11.2, 20.02.1
openvswitch (Red Hat package) - update to 2.13.0-25.el8fdp.1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
dpdk - update to 19.11.1-2.fc32
dpdk (Red Hat package) - addressed in versions 19.11.3-1.el8, 19.11-5.el8_2
dpdk - update to 19.11-5
dpdk-devel - update to 19.11-5
dpdk-tools - update to 19.11-5
dpdk-doc - update to 19.11-5

External References

Related Security Bulletins