ALT-PU-2020-3518-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2020-14374
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1599
- openSUSE-SU-2020:1599
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- https://bugzilla.redhat.com/show_bug.cgi?id=1879466
- https://bugzilla.redhat.com/show_bug.cgi?id=1879466
- https://www.openwall.com/lists/oss-security/2020/09/28/3
- https://www.openwall.com/lists/oss-security/2020/09/28/3
Modified: 2024-11-21
CVE-2020-14375
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1599
- openSUSE-SU-2020:1599
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- https://bugzilla.redhat.com/show_bug.cgi?id=1879468
- https://bugzilla.redhat.com/show_bug.cgi?id=1879468
- USN-4550-1
- USN-4550-1
- https://www.openwall.com/lists/oss-security/2020/09/28/3
- https://www.openwall.com/lists/oss-security/2020/09/28/3
Modified: 2024-11-21
CVE-2020-14376
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1599
- openSUSE-SU-2020:1599
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- https://bugzilla.redhat.com/show_bug.cgi?id=1879470
- https://bugzilla.redhat.com/show_bug.cgi?id=1879470
- USN-4550-1
- USN-4550-1
- https://www.openwall.com/lists/oss-security/2020/09/28/3
- https://www.openwall.com/lists/oss-security/2020/09/28/3
Modified: 2024-11-21
CVE-2020-14377
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual machine to read significant amounts of host memory. The highest threat from this vulnerability is to data confidentiality and system availability.
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1599
- openSUSE-SU-2020:1599
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- https://bugzilla.redhat.com/show_bug.cgi?id=1879472
- https://bugzilla.redhat.com/show_bug.cgi?id=1879472
- USN-4550-1
- USN-4550-1
- https://www.openwall.com/lists/oss-security/2020/09/28/3
- https://www.openwall.com/lists/oss-security/2020/09/28/3
Modified: 2024-11-21
CVE-2020-14378
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1593
- openSUSE-SU-2020:1599
- openSUSE-SU-2020:1599
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- [oss-security] 20210104 Re: [dpdk-dev] DPDK security advisory for multiple vhost crypto issues
- https://bugzilla.redhat.com/show_bug.cgi?id=1879473
- https://bugzilla.redhat.com/show_bug.cgi?id=1879473
- USN-4550-1
- USN-4550-1
- https://www.openwall.com/lists/oss-security/2020/09/28/3
- https://www.openwall.com/lists/oss-security/2020/09/28/3