Memory leak in DPDK - CVE-2020-10726

 

Memory leak in DPDK - CVE-2020-10726

Published: May 19, 2020 / Updated: May 26, 2020


Vulnerability identifier: #VU27999
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10726
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak, related to fd leak and vring index check. A remote attacker can force the application to leak memory and read sensitive information or perform denial of service attack.


Affected software

DPDK
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.12 (Red Hat package)
dpdk (Ubuntu package)
dpdk
dpdk (Red Hat package)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora

How to mitigate CVE-2020-10726

Install updates from vendor's website.

DPDK - addressed in versions 19.11.2, 20.02.1
openvswitch (Red Hat package) - update to 2.13.0-25.el8fdp.1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
dpdk - update to 19.11.1-2.fc32
dpdk (Red Hat package) - update to 19.11.3-1.el8

External References

Related Security Bulletins