Information Leak Vulnerability in DPDK's vhost-crypto Library
CVE-2020-10724
5.1MEDIUM
What is CVE-2020-10724?
A vulnerability exists within the vhost-crypto library of DPDK versions 18.11 and above, where insufficient validation of user-supplied data can lead to information leakage via an out-of-bounds memory read. This absence of checks creates potential risks, allowing attackers to expose sensitive data that should remain protected.
Affected Version(s)
dpdk 20.02.1
dpdk 19.11.2
dpdk 18.11.8