Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1983

Опубликовано: 02 апр. 2020
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

A use-after-free flaw was found in the SLiRP networking implementation of the QEMU emulator. Specifically, this flaw occurs in the ip_reass() routine while reassembling incoming IP fragments whose combined size is bigger than 65k. This flaw allows an attacker to crash the QEMU process on the host, resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kvmOut of support scope
Red Hat Enterprise Linux 6qemu-kvmWill not fix
Red Hat Enterprise Linux 7slirp4netnsWill not fix
Red Hat Enterprise Linux 8container-tools:1.0/slirp4netnsOut of support scope
Red Hat Enterprise Linux 8container-tools:2.0/slirp4netnsAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.1/qemu-kvmAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmAffected
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/qemu-kvmNot affected
Red Hat Enterprise Linux 9qemu-kvmNot affected
Red Hat OpenShift Container Platform 4slirp4netnsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1829825QEMU: slirp: use-after-free in ip_reass() function in ip_input.c

EPSS

Процентиль: 35%
0.00141
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVSS3: 7.5
nvd
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.

CVSS3: 7.5
debian
около 5 лет назад

A use after free vulnerability in ip_reass() in ip_input.c of libslirp ...

suse-cvrf
около 5 лет назад

Security update for qemu

suse-cvrf
около 5 лет назад

Security update for slirp4netns

EPSS

Процентиль: 35%
0.00141
Низкий

6.5 Medium

CVSS3