CVE-2020-10723
published 2020-05-19CVE-2020-10723: A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain…
PriorityP429medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.38%
30.1th percentile
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | dpdk | < dpdk 19.11.2-1 (bookworm) | dpdk 19.11.2-1 (bookworm) |
| dpdk | data_plane_development_kit | <= 17.05 | — |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 19.11.2-1 | 19.11.2-1 |
| dpdk | dpdk | >= 0 < 17.11.9-0ubuntu18.04.2 | 17.11.9-0ubuntu18.04.2 |
| dpdk | dpdk | >= 0 < 19.11.1-0ubuntu1.1 | 19.11.1-0ubuntu1.1 |
| fedoraproject | fedora | — | — |
| msrc | azl3_ceph_18.2.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_ceph_18.2.2-8_on_azure_linux_3.0 | — | — |
| msrc | cbl2_ceph_16.2.10-7_on_cbl_mariner_2.0 | — | — |
| opensuse | leap | — | — |
| oracle | communications_session_border_controller | 8.2 – 8.4 | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_communications_broker | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv6.7MEDIUM
vendor_oracle6.7MEDIUM
vendor_debian5.1MEDIUM
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: System (DPDK) — CVE-2020-10723
vendor_oracle·2021-01-15·CVSS 6.7
CVE-2020-10723 [MEDIUM] Oracle Oracle Communications Risk Matrix: System (DPDK) — CVE-2020-10723
Oracle Oracle Communications Risk Matrix: System (DPDK) vulnerability
CVE: CVE-2020-10723
CVSS: 6.7
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2021 (JAN 2021)
Red Hat
dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
vendor_redhat·2020-05-18·CVSS 5.1
CVE-2020-10723 [MEDIUM] CWE-190 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
Statement: This issue did not affect the versions of Ceph as shipped with Red Hat Ceph Storage 3 and 4, as they di
Ubuntu
DPDK vulnerabilities
vendor_ubuntu·2020-05-18·CVSS 5.1
CVE-2020-10722 [MEDIUM] DPDK vulnerabilities
Title: DPDK vulnerabilities
Summary: Several security issues were fixed in DPDK.
It was discovered that DPDK incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2020-10722, CVE-2020-10723,
CVE-2020-10724, CVE-2020-10725, CVE-2020-10726)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
A memory corruption issue was found in DPDK versions 17.05 and above
vendor_msrc·2020-05-12·CVSS 5.1
CVE-2020-10723 [MEDIUM] CWE-190 A memory corruption issue was found in DPDK versions 17.05 and above
A memory corruption issue was found in DPDK versions 17.05 and above
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference
Debian
CVE-2020-10723: dpdk - A memory corruption issue was found in DPDK versions 17.05 and above. This flaw ...
vendor_debian·2020·CVSS 5.1
CVE-2020-10723 [MEDIUM] CVE-2020-10723: dpdk - A memory corruption issue was found in DPDK versions 17.05 and above. This flaw ...
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
Scope: local
bookworm: resolved (fixed in 19.11.2-1)
bullseye: resolved (fixed in 19.11.2-1)
forky: resolved (fixed in 19.11.2-1)
sid: resolved (fixed in 19.11.2-1)
trixie: resolved (fixed in 19.11.2-1)
GHSA
GHSA-4gq2-9rxc-45pg: A memory corruption issue was found in DPDK versions 17
ghsa_unreviewed·2022-05-24
CVE-2020-10723 [MEDIUM] CWE-190 GHSA-4gq2-9rxc-45pg: A memory corruption issue was found in DPDK versions 17
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
OSV
CVE-2020-10723: A memory corruption issue was found in DPDK versions 17
osv·2020-05-19·CVSS 6.7
CVE-2020-10723 [MEDIUM] CVE-2020-10723: A memory corruption issue was found in DPDK versions 17
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
OSV
dpdk vulnerabilities
osv·2020-05-18·CVSS 6.7
CVE-2020-10722 [MEDIUM] dpdk vulnerabilities
dpdk vulnerabilities
It was discovered that DPDK incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or
execute arbitrary code. (CVE-2020-10722, CVE-2020-10723,
CVE-2020-10724, CVE-2020-10725, CVE-2020-10726)
No detection rules found.
No public exploits indexed.
Bugzilla
Update to dpdk-19.11.3
bugzilla·2020-09-01·CVSS 5.1
CVE-2020-10722 [MEDIUM] Update to dpdk-19.11.3
Update to dpdk-19.11.3
Update rawhide / f33 dpdk package to dpdk 19.11.3 that also includes the fixes for the following CVEs:
CVE-2020-10722
CVE-2020-10723
CVE-2020-10724
CVE-2020-10725
CVE-2020-10726
Discussion:
FEDORA-2020-8d56b5b55c has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2020-8d56b5b55c
---
FEDORA-2020-8d56b5b55c has been pushed to the Fedora 33 testing repository.
In short time you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-8d56b5b55c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-8d56b5b55c
See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test up
Bugzilla
CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() [fedora-all]
bugzilla·2020-05-18·CVSS 5.1
CVE-2020-10723 [MEDIUM] CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() [fedora-all]
CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
bugzilla·2020-04-28·CVSS 5.1
CVE-2020-10723 [MEDIUM] CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
CVE-2020-10723 dpdk: librte_vhost Integer truncation in vhost_user_check_and_alloc_queue_pair()
A vulnerability was found in DPDK through version 18.11, vhost_user_check_and_alloc_queue_pair() is used to extract a vring index from a payload. This function validates the index and is called early on in when performing message handling. Most message handlers depend on it correctly validating the vring index. Depending on the message type the vring index is in different parts of the payload. The function contains a switch/case for each type and copies the index. This is stored in a uint16. This index is then validated. Depending on the message, the source index is an unsigned int. If integer truncation occurs (uint->uint16) the top 16 bits of the index are never validated. When they are used
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00045.htmlhttps://bugs.dpdk.org/show_bug.cgi?id=268https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10723https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRHKFVV4MRWNNJOYQOVP64L4UVWYPEO4/https://usn.ubuntu.com/4362-1/https://www.openwall.com/lists/oss-security/2020/05/18/2https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00045.htmlhttps://bugs.dpdk.org/show_bug.cgi?id=268https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10723https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRHKFVV4MRWNNJOYQOVP64L4UVWYPEO4/https://usn.ubuntu.com/4362-1/https://www.openwall.com/lists/oss-security/2020/05/18/2https://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.html
2020-05-19
Published