CVE-2020-10722: Canonical Ubuntu Linux

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.10 only; version 20.04 only
  • Dpdk Data Plane Development Kit: up to and including 18.05
  • Fedoraproject Fedora: version 32 only
  • Opensuse Leap: version 15.1 only
  • Oracle Communications Session Border Controller: from 8.2, up to and including 8.4
  • Oracle Enterprise Communications Broker: version 3.1.0 only; version 3.2.0 only

Published 2020-05-19. Last modified 2026-06-17.