Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38821.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-38821
Upstream
Published
2020-09-30T19:15:12Z
Modified
2026-04-01T05:13:21.169882Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
CVE-2020-14378 affecting package ceph for versions less than 18.2.2-1
Details

An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the move_desc function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause move_desc to get stuck in a 4,294,967,295-count iteration loop. Depending on how vhost_crypto is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.

References

Affected packages

Azure Linux:3 / ceph

Package

Name
ceph
Purl
pkg:rpm/azure-linux/ceph

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
18.2.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-38821.json"