Permissions, Privileges, and Access Controls in DPDK - CVE-2020-14375
Published: September 30, 2020 / Updated: October 5, 2020
Vulnerability details
The vulnerability allows a remote user to compromise the host OS.
The vulnerability exists due to Virtio ring descriptors and the data they describe are in a region of
memory accessible by from both the virtual machine and the host. An attacker with access to the guest OS can change the contents of the memory after vhost_crypto has validated it and execute arbitrary code on the host OS.
Affected software
Opensuse
openEuler
Ubuntu
dpdk (Ubuntu package)
dpdk
dpdk-doc
dpdk-devel
dpdk-debugsource
dpdk-debuginfo
dpdk-tools
How to mitigate CVE-2020-14375
dpdk (Ubuntu package) - update to 19.11.3-0ubuntu0.2
dpdk - update to 19.11-5
dpdk-doc - update to 19.11-5
dpdk-devel - update to 19.11-5
dpdk-debugsource - update to 19.11-5
dpdk-debuginfo - update to 19.11-5
dpdk-tools - update to 19.11-5