Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libslirp | fixed | 4.9.5-1 | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2537747
Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/b4b2b07812fcadd2754281e5ae8d9fe2bfb3c96a (v4.9.5)
Связанные уязвимости
CVSS3: 4.3
redhat
3 дня назад
An out-of-bounds read was found in the NC-SI OEM response handler of libslirp. A truncated NC-SI OEM Ethernet frame causes ncsi_rsp_handler_oem() to read up to 4 bytes beyond the supplied packet length and reflect the value into the response sent to the guest, resulting in guest-observable disclosure of adjacent host process memory.