CVE-2020-10722
published 2020-05-19CVE-2020-10722: A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller…
PriorityP427medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.1th percentile
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | dpdk | < dpdk 19.11.2-1 (bookworm) | dpdk 19.11.2-1 (bookworm) |
| dpdk | data_plane_development_kit | <= 18.05 | — |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 17.11.9-0ubuntu18.04.2 | 17.11.9-0ubuntu18.04.2 |
| dpdk | dpdk | >= 0 < 19.11.1-0ubuntu1.1 | 19.11.1-0ubuntu1.1 |
| fedoraproject | fedora | — | — |
| msrc | azl3_ceph_18.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| opensuse | leap | — | — |
| oracle | communications_session_border_controller | 8.2 – 8.4 | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_communications_broker | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.7MEDIUM
vendor_oracle6.7MEDIUM
vendor_debian5.1MEDIUM
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63gx-gp99-wcgc: A vulnerability was found in DPDK versions 18
ghsa_unreviewed·2022-05-24
CVE-2020-10722 [MEDIUM] CWE-190 GHSA-63gx-gp99-wcgc: A vulnerability was found in DPDK versions 18
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
OSV
CVE-2020-10722: A vulnerability was found in DPDK versions 18
osv·2020-05-19·CVSS 6.7
CVE-2020-10722 [MEDIUM] CVE-2020-10722: A vulnerability was found in DPDK versions 18
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
OSV
dpdk vulnerabilities
osv·2020-05-18·CVSS 6.7
CVE-2020-10722 [MEDIUM] dpdk vulnerabilities
dpdk vulnerabilities
It was discovered that DPDK incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2020-10722, CVE-2020-10723,
CVE-2020-10724, CVE-2020-10725, CVE-2020-10726)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (DPDK) — CVE-2020-10722
vendor_oracle·2020-10-15·CVSS 6.7
CVE-2020-10722 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (DPDK) — CVE-2020-10722
Oracle Oracle Communications Risk Matrix: Platform (DPDK) vulnerability
CVE: CVE-2020-10722
CVSS: 6.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuoct2020 (OCT 2020)
Ubuntu
DPDK vulnerabilities
vendor_ubuntu·2020-05-18·CVSS 5.1
CVE-2020-10722 [MEDIUM] DPDK vulnerabilities
Title: DPDK vulnerabilities
Summary: Several security issues were fixed in DPDK.
It was discovered that DPDK incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2020-10722, CVE-2020-10723,
CVE-2020-10724, CVE-2020-10725, CVE-2020-10726)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
vendor_redhat·2020-05-18·CVSS 5.1
CVE-2020-10722 [MEDIUM] CWE-190 dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
Statement: This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they did not include support for DPDK.
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Will not fix
Package: openvswitch2.12 (Fast Datapath for RHEL 7) - Will not fix
Package: op
Microsoft
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing
vendor_msrc·2020-05-12·CVSS 5.1
CVE-2020-10722 [MEDIUM] CWE-190 A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified,
Debian
CVE-2020-10722: dpdk - A vulnerability was found in DPDK versions 18.05 and above. A missing check for ...
vendor_debian·2020·CVSS 5.1
CVE-2020-10722 [MEDIUM] CVE-2020-10722: dpdk - A vulnerability was found in DPDK versions 18.05 and above. A missing check for ...
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
Scope: local
bookworm: resolved (fixed in 19.11.2-1)
bullseye: resolved (fixed in 19.11.2-1)
forky: resolved (fixed in 19.11.2-1)
sid: resolved (fixed in 19.11.2-1)
trixie: resolved (fixed in 19.11.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
Update to dpdk-19.11.3
bugzilla·2020-09-01·CVSS 5.1
CVE-2020-10722 [MEDIUM] Update to dpdk-19.11.3
Update to dpdk-19.11.3
Update rawhide / f33 dpdk package to dpdk 19.11.3 that also includes the fixes for the following CVEs:
CVE-2020-10722
CVE-2020-10723
CVE-2020-10724
CVE-2020-10725
CVE-2020-10726
Discussion:
FEDORA-2020-8d56b5b55c has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2020-8d56b5b55c
---
FEDORA-2020-8d56b5b55c has been pushed to the Fedora 33 testing repository.
In short time you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-8d56b5b55c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-8d56b5b55c
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test up
Bugzilla
CVE-2020-10722 dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() [fedora-all]
bugzilla·2020-05-18·CVSS 5.1
CVE-2020-10722 [MEDIUM] CVE-2020-10722 dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() [fedora-all]
CVE-2020-10722 dpdk: librte_vhost Interger overflow in vhost_user_set_log_base() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2020-10722 dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
bugzilla·2020-04-28·CVSS 5.1
CVE-2020-10722 [MEDIUM] CVE-2020-10722 dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
CVE-2020-10722 dpdk: librte_vhost Integer overflow in vhost_user_set_log_base()
A vulnerability was found in DPDK through version 18.11, vhost_user_set_log_base() is a message handler that is called to handle the VHOST_USER_SET_LOG_BASE message. Its payload contains a 64 bit size and offset. Both are added up and used as a size when calling mmap(). There is no integer overflow check. If an integer overflow occurs a smaller memory map would be created than requested. Since the returned mapping is mapped as writable and used for logging, it seems highly likely that memory corruption can occur.
Discussion:
Acknowledgments:
Name: Ferruh Yigit (Reporter)
---
Removed OpenStack 7 affects and added missing affects for OpenStack and FastDatapath.
---
It seems to me this flaw was introduced
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00045.htmlhttps://bugs.dpdk.org/show_bug.cgi?id=267https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10722https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRHKFVV4MRWNNJOYQOVP64L4UVWYPEO4/https://usn.ubuntu.com/4362-1/https://www.openwall.com/lists/oss-security/2020/05/18/2https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00045.htmlhttps://bugs.dpdk.org/show_bug.cgi?id=267https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10722https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRHKFVV4MRWNNJOYQOVP64L4UVWYPEO4/https://usn.ubuntu.com/4362-1/https://www.openwall.com/lists/oss-security/2020/05/18/2https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-05-19
Published