An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.
2020-09-30T19:15:12.993
2024-11-21T05:03:07.920
Modified
CVSSv3.1: 3.3 (LOW)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | dpdk | data_plane_development_kit | < 18.11.10 | Yes |
| Application | dpdk | data_plane_development_kit | < 19.11.5 | Yes |
| Operating System | canonical | ubuntu_linux | 20.04 | Yes |
| Operating System | opensuse | leap | 15.1 | Yes |
| Operating System | opensuse | leap | 15.2 | Yes |