#VU47309 Permissions, Privileges, and Access Controls in DPDK - CVE-2020-14375
Published: September 30, 2020 / Updated: October 5, 2020
DPDK
DPDK Project
Description
The vulnerability allows a remote user to compromise the host OS.
The vulnerability exists due to Virtio ring descriptors and the data they describe are in a region of
memory accessible by from both the virtual machine and the host. An attacker with access to the guest OS can change the contents of the memory after vhost_crypto has validated it and execute arbitrary code on the host OS.