QEMU: Slirp: use-after-free during packet reassembly
Published Sep 6, 2019
7.5
HIGHCVSS 3.1
EPSS 3.99%
Description
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
Affected products
No data.
Configuration 1
- 4.0.0
No data.
Advanced Virtualization for RHEL 8.2.1
virt-devel:8.2-8020120200707202843.11e3e113
Fixed · RHBA-2020:3172
Advanced Virtualization for RHEL 8.2.1
virt:8.2-8020120200707202843.11e3e113
Fixed · RHBA-2020:3172
Red Hat Enterprise Linux 6
qemu-kvm-2:0.12.1.2-2.506.el6_10.6
Fixed · RHSA-2020:0775
Red Hat Enterprise Linux 7 Extras
slirp4netns-0:0.3.0-8.el7_7
Fixed · RHSA-2020:0889
Red Hat Enterprise Linux 8
container-tools:rhel8-8010120200116121758.53d07e52
Fixed · RHSA-2020:0348
Red Hat Enterprise Linux 8
virt-devel:rhel-8030020200909014558.30b713e6
Fixed · RHSA-2020:4676
Red Hat Enterprise Linux 8
virt:rhel-8030020200909014558.30b713e6
Fixed · RHSA-2020:4676
Red Hat Enterprise Linux 5
kvm
Out of support scope
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 7
qemu-kvm
Will not fix
Red Hat Enterprise Linux 7
qemu-kvm-ma
Will not fix
Red Hat Enterprise Linux 7
qemu-kvm-rhev
Will not fix
Red Hat Enterprise Linux 8
container-tools:1.0/slirp4netns
Out of support scope
Red Hat Enterprise Linux 8 Advanced Virtualization
qemu-kvm
Affected
Red Hat OpenShift Container Platform 4
slirp4netns
Not affected
Red Hat OpenStack Platform 10 (Newton)
qemu-kvm-rhev
Fix deferred
Red Hat OpenStack Platform 13 (Queens)
qemu-kvm-rhev
Fix deferred
Red Hat OpenStack Platform 14 (Rocky)
qemu-kvm-rhev
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Advanced Virtualization for RHEL 8.2.1 | virt-devel:8.2-8020120200707202843.11e3e113 | Fixed | RHBA-2020:3172 |
| Advanced Virtualization for RHEL 8.2.1 | virt:8.2-8020120200707202843.11e3e113 | Fixed | RHBA-2020:3172 |
| Red Hat Enterprise Linux 6 | qemu-kvm-2:0.12.1.2-2.506.el6_10.6 | Fixed | RHSA-2020:0775 |
| Red Hat Enterprise Linux 7 Extras | slirp4netns-0:0.3.0-8.el7_7 | Fixed | RHSA-2020:0889 |
| Red Hat Enterprise Linux 8 | container-tools:rhel8-8010120200116121758.53d07e52 | Fixed | RHSA-2020:0348 |
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8030020200909014558.30b713e6 | Fixed | RHSA-2020:4676 |
| Red Hat Enterprise Linux 8 | virt:rhel-8030020200909014558.30b713e6 | Fixed | RHSA-2020:4676 |
| Red Hat Enterprise Linux 5 | kvm | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | container-tools:1.0/slirp4netns | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | qemu-kvm | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | slirp4netns | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | qemu-kvm-rhev | Fix deferred | n/a |
| Red Hat OpenStack Platform 13 (Queens) | qemu-kvm-rhev | Fix deferred | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | qemu-kvm-rhev | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat OpenStack Platform: * This flaw impacts KVM user-mode or SLIRP networking, which is not used in Red Hat OpenStack Platform. Although updating is recommended for affected versions (see below), Red Hat OpenStack Platform environments are not vulnerable.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00034.html vendor-advisoryx_refsource_SUSE
- http://www.openwall.com/lists/oss-security/2019/09/06/3 x_refsource_CONFIRMMailing ListPatchThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0775 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-15890 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1749716 Issue Tracking
- https://gitlab.freedesktop.org/slirp/libslirp/commit/c5927943 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00021.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-15890
- https://seclists.org/bugtraq/2020/Feb/0 mailing-listx_refsource_BUGTRAQ
- https://usn.ubuntu.com/4191-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4191-2/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-15890
- https://www.debian.org/security/2020/dsa-4616 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.