Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3594

Опубликовано: 14 июн. 2021
Источник: redhat
CVSS3: 3.8
EPSS Низкий

Описание

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality.

Отчет

This flaw affects the versions of SLiRP embedded in qemu-kvm as shipped with Red Hat Enterprise Linux 8 and RHEL Advanced Virtualization. A future update may address this issue. It is worth noting that although qemu-kvm is built with SLiRP networking support, due to its limitations, it is not used by the virtual machine guests by default.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvmOut of support scope
Red Hat Enterprise Linux 7qemu-kvm-maOut of support scope
Red Hat Enterprise Linux 7qemu-kvm-rhevOut of support scope
Red Hat Enterprise Linux 8container-tools:3.0/libslirpFix deferred
Red Hat Enterprise Linux 8container-tools:rhel8/libslirpFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.2/qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:8.3/qemu-kvmFix deferred
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/qemu-kvmAffected
Red Hat Enterprise Linux 9libslirpNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=1970491QEMU: slirp: invalid pointer initialization may lead to information disclosure (udp)

EPSS

Процентиль: 3%
0.00018
Низкий

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 3.8
ubuntu
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
nvd
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
debian
около 4 лет назад

An invalid pointer initialization issue was found in the SLiRP network ...

CVSS3: 3.8
github
около 3 лет назад

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

CVSS3: 3.8
fstec
около 4 лет назад

Уязвимость функции udp_input() компонента src/udp.c эмулятора TCP-IP Libslirp, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 3%
0.00018
Низкий

3.8 Low

CVSS3