Описание
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libslirp | fixed | 4.9.5-1 | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=2537748
Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/97f2dd0afea0db8b31135f768ecafe0775722a25 (v4.9.5)
Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/5815f119c334c26e6e7a14ac87eca12b69918627 (v4.9.5)
CVE description is wrong, per https://gitlab.freedesktop.org/slirp/libslirp/-/commit/62b298621dfc413a42d2181933f5335815afa1a4
is only for the DHCPv6 part
EPSS
Связанные уязвимости
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
EPSS