CVE-2020-10723: Canonical Ubuntu Linux

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only; version 19.10 only; version 20.04 only
  • Dpdk Data Plane Development Kit: up to and including 17.05
  • Fedoraproject Fedora: version 32 only
  • Opensuse Leap: version 15.1 only
  • Oracle Communications Session Border Controller: from 8.2, up to and including 8.4
  • Oracle Enterprise Communications Broker: version 3.1.0 only; version 3.2.0 only

Published 2020-05-19. Last modified 2026-06-17.