Описание
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
A use-after-free issue was found in the SLiRP networking implementation of the QEMU emulator. The issue occurs in ip_reass() routine while reassembling incoming packets, if the first fragment is bigger than the m->m_dat[] buffer. A user or process could use this flaw to crash the QEMU process on the host, resulting in a denial of service.
Отчет
Red Hat OpenStack Platform:
- This flaw impacts KVM user-mode or SLIRP networking, which is not used in Red Hat OpenStack Platform. Although updating is recommended for affected versions (see below), Red Hat OpenStack Platform environments are not vulnerable.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | kvm | Out of support scope | ||
Red Hat Enterprise Linux 5 | xen | Not affected | ||
Red Hat Enterprise Linux 7 | qemu-kvm | Will not fix | ||
Red Hat Enterprise Linux 7 | qemu-kvm-ma | Will not fix | ||
Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Will not fix | ||
Red Hat Enterprise Linux 8 | container-tools:1.0/slirp4netns | Out of support scope | ||
Red Hat Enterprise Linux 8 Advanced Virtualization | qemu-kvm | Affected | ||
Red Hat OpenShift Container Platform 4 | slirp4netns | Not affected | ||
Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Fix deferred | ||
Red Hat OpenStack Platform 13 (Queens) | qemu-kvm-rhev | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.6 Medium
CVSS3
Связанные уязвимости
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reas ...
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
Уязвимость функции ip_reass (ip_input.с) аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании
5.6 Medium
CVSS3