Information Leak Vulnerability in DPDK's vhost-crypto Library
CVE-2020-10724

5.1MEDIUM

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
19 May 2020

What is CVE-2020-10724?

A vulnerability exists within the vhost-crypto library of DPDK versions 18.11 and above, where insufficient validation of user-supplied data can lead to information leakage via an out-of-bounds memory read. This absence of checks creates potential risks, allowing attackers to expose sensitive data that should remain protected.

Affected Version(s)

dpdk 20.02.1

dpdk 19.11.2

dpdk 18.11.8

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.