Memory leak in DPDK - CVE-2020-10726
Published: May 19, 2020 / Updated: May 26, 2020
Vulnerability identifier: #VU27999
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10726
CWE-ID: CWE-401
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak, related to fd leak and vring index check. A remote attacker can force the application to leak memory and read sensitive information or perform denial of service attack.
Affected software
DPDK
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.12 (Red Hat package)
dpdk (Ubuntu package)
dpdk
dpdk (Red Hat package)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
openvswitch (Red Hat package)
openvswitch2.10 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.12 (Red Hat package)
dpdk (Ubuntu package)
dpdk
dpdk (Red Hat package)
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
How to mitigate CVE-2020-10726
Install updates from vendor's website.
DPDK - addressed in versions 19.11.2, 20.02.1
openvswitch (Red Hat package) - update to 2.13.0-25.el8fdp.1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
dpdk - update to 19.11.1-2.fc32
dpdk (Red Hat package) - update to 19.11.3-1.el8
openvswitch (Red Hat package) - update to 2.13.0-25.el8fdp.1
dpdk (Ubuntu package) - addressed in versions 17.11.9-0ubuntu18.04.2, 18.11.5-0ubuntu0.19.10.2, 19.11.1-0ubuntu1.1
dpdk - update to 19.11.1-2.fc32
dpdk (Red Hat package) - update to 19.11.3-1.el8