QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
Published Nov 26, 2020
4.3
MEDIUMCVSS 3.1
EPSS 1.46%
Description
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Affected products
No data.
Configuration 1
- ≤ 4.3.1
Configuration 2
- 32
- 33
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 8
virt-devel:rhel-8040020210317013608.9f9e2e7e
Fixed · RHSA-2021:1762
Red Hat Enterprise Linux 8
virt:rhel-8040020210317013608.9f9e2e7e
Fixed · RHSA-2021:1762
Red Hat Enterprise Linux 5
kvm
Out of support scope
Red Hat Enterprise Linux 5
xen
Not affected
Red Hat Enterprise Linux 6
qemu-kvm
Out of support scope
Red Hat Enterprise Linux 7
qemu-kvm
Fix deferred
Red Hat Enterprise Linux 7
qemu-kvm-ma
Fix deferred
Red Hat Enterprise Linux 7
qemu-kvm-rhev
Fix deferred
Red Hat Enterprise Linux 8 Advanced Virtualization
virt:8.3/qemu-kvm
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | virt-devel:rhel-8040020210317013608.9f9e2e7e | Fixed | RHSA-2021:1762 |
| Red Hat Enterprise Linux 8 | virt:rhel-8040020210317013608.9f9e2e7e | Fixed | RHSA-2021:1762 |
| Red Hat Enterprise Linux 5 | kvm | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | xen | Not affected | n/a |
| Red Hat Enterprise Linux 6 | qemu-kvm | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-ma | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | qemu-kvm-rhev | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 Advanced Virtualization | virt:8.3/qemu-kvm | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- http://www.openwall.com/lists/oss-security/2020/11/27/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-29129 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1902231 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-21510 Advisory
- https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45S5IHSWYITJKMRT23HCHJQDI674AMTQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPCOHDEONMHH6QPJZKRLLCNRGRYODG7X/ vendor-advisoryx_refsource_FEDORA
- https://lists.freedesktop.org/archives/slirp/2020-November/000115.html x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-29129
- https://www.cve.org/CVERecord?id=CVE-2020-29129
- https://www.openwall.com/lists/oss-security/2020/11/27/1
Change history (0)
No recorded changes yet.