Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-95507

Опубликовано: 22 сент. 2026
Источник: redhat
CVSS3: 4.3

Описание

An out-of-bounds read was found in the NC-SI OEM response handler of libslirp. A truncated NC-SI OEM Ethernet frame causes ncsi_rsp_handler_oem() to read up to 4 bytes beyond the supplied packet length and reflect the value into the response sent to the guest, resulting in guest-observable disclosure of adjacent host process memory.

Отчет

Moderate: A flaw in libslirp's NC-SI OEM response handler allows a malicious guest to trigger an out-of-bounds read, leading to the disclosure of up to 4 bytes of adjacent host RX-buffer memory. This bounded memory disclosure is guest-triggerable and does not involve write access or code execution on the host.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libslirpNot affected
Red Hat Enterprise Linux 8container-tools:rhel8/libslirpNot affected
Red Hat Enterprise Linux 9libslirpNot affected
Red Hat OpenShift Container Platform 4libslirpNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Not affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2537747libslirp: libslirp: out-of-bounds read in NC-SI OEM response handler discloses host memory to guest

4.3 Medium

CVSS3

Связанные уязвимости

ubuntu
4 дня назад

[Unknown description]

debian

Описание отсутствует

4.3 Medium

CVSS3