Vulnerability CVE-2021-3595: Information

Description

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

Severity: LOW (3.8) Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Published: June 16, 2021
Modified: Nov. 7, 2023
Error type identifier: CWE-824

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libslirpsisyphus4.6.1-alt14.7.0-alt1ALT-PU-2021-2279-1279793Fixed
libslirpsisyphus_riscv644.6.1-alt14.7.0-alt1ALT-PU-2022-3500-1-Fixed
libslirpp104.6.1-alt14.7.0-alt1ALT-PU-2021-2279-1279793Fixed
libslirpc10f14.6.1-alt14.7.0-alt1ALT-PU-2021-2279-1279793Fixed
libslirpc9f24.7.0-alt14.7.0-alt1ALT-PU-2022-3194-1309993Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:libslirp_project:libslirp:*:*:*:*:*:*:*:*
      End excliding
      4.6.0

      Configuration 2

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:advanced_virtualization:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

      cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*