Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-95508

Опубликовано: 22 сент. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

Меры по смягчению последствий

Do not configure SlirpConfig.if_mtu below the IPv6 minimum link MTU of 1280.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libslirpAffected
Red Hat Enterprise Linux 8container-tools:rhel8/libslirpAffected
Red Hat Enterprise Linux 9libslirpAffected
Red Hat OpenShift Container Platform 4libslirpAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2537748libslirp: libslirp: heap buffer overflow in DHCPv6/TFTP response builders on small interface MTU

EPSS

Процентиль: 36%
0.00423
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

CVSS3: 7.4
nvd
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

CVSS3: 7
msrc
около 11 часов назад

Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu

CVSS3: 7.4
debian
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response ...

CVSS3: 7.4
github
3 дня назад

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

EPSS

Процентиль: 36%
0.00423
Низкий

7.4 High

CVSS3