Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-95508

Опубликовано: 22 сент. 2026
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

EPSS

Процентиль: 45%
0.0057
Низкий

7.4 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

CVSS3: 7.4
redhat
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

CVSS3: 7
msrc
около 11 часов назад

Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu

CVSS3: 7.4
debian
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response ...

CVSS3: 7.4
github
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

EPSS

Процентиль: 45%
0.0057
Низкий

7.4 High

CVSS3

Дефекты

CWE-787