Search CVE reports
1 – 10 of 16 results
[Unknown description]
1 affected package
libslirp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the...
1 affected package
libslirp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | — |
Some fixes available 3 of 5
An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker...
1 affected package
libslirp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | Fixed | Fixed | Fixed | Needs evaluation | — |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the...
2 affected packages
libslirp, qemu
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | — | Fixed | Fixed | Fixed | Not in release |
| qemu | — | Not affected | Not affected | Not affected | Fixed |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the...
2 affected packages
libslirp, qemu
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | — | Fixed | Fixed | Fixed | Not in release |
| qemu | — | Not affected | Not affected | Not affected | Fixed |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the...
2 affected packages
libslirp, qemu
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | Fixed | Fixed | Fixed | Fixed | Not in release |
| qemu | Not affected | Not affected | Not affected | Not affected | Fixed |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the...
2 affected packages
libslirp, qemu
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | — | Fixed | Fixed | Fixed | Not in release |
| qemu | — | Not affected | Not affected | Not affected | Fixed |
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
3 affected packages
libslirp, qemu, qemu-kvm
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | — | — | Not affected | Fixed | Not in release |
| qemu | — | — | Not affected | Not affected | Not affected |
| qemu-kvm | — | — | Not in release | Not in release | Not in release |
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
3 affected packages
libslirp, qemu, qemu-kvm
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | — | Not affected | Not affected | Fixed | Not in release |
| qemu | — | Not affected | Not affected | Not affected | Not affected |
| qemu-kvm | — | Not in release | Not in release | Not in release | Not in release |
Some fixes available 2 of 5
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This...
4 affected packages
libslirp, qemu, qemu-kvm, slirp4netns
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| libslirp | Not affected | Not affected | Not affected | Fixed | Not in release |
| qemu | Not affected | Not affected | Not affected | Not affected | Fixed |
| qemu-kvm | Not in release | Not in release | Not in release | Not in release | Not in release |
| slirp4netns | Not affected | Not affected | Not affected | Vulnerable | Not in release |