CVE-2020-10756
published 2020-07-09CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply()…
PriorityP428medium6.5CVSS 3.1
AVLACLPRLUINSCCHINAN
EPSS
0.51%
40.2th percentile
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libslirp | < libslirp 4.3.1-1 (bookworm) | libslirp 4.3.1-1 (bookworm) |
| debian | qemu | < libslirp 4.3.1-1 (bookworm) | libslirp 4.3.1-1 (bookworm) |
| debian | qemu | — | — |
| debian | slirp4netns | < libslirp 4.3.1-1 (bookworm) | libslirp 4.3.1-1 (bookworm) |
| libslirp_project | libslirp | < 4.3.1 | 4.3.1 |
| libslirp_project | libslirp | >= 0 < 4.3.1-1 | 4.3.1-1 |
| libslirp_project | libslirp | >= 0 < 4.3.1-1 | 4.3.1-1 |
| libslirp_project | libslirp | >= 0 < 4.3.1-1 | 4.3.1-1 |
| libslirp_project | libslirp | >= 0 < 4.3.1-1 | 4.3.1-1 |
| msrc | cm1_qemu-kvm_4.2.0-48_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| qemu | qemu | < 4.2.0-34 | 4.2.0-34 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:2.5+dfsg-5ubuntu10.45 | 1:2.5+dfsg-5ubuntu10.45 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.31 | 1:2.11+dfsg-1ubuntu7.31 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.4 | 1:4.2-3ubuntu6.4 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rjqx-xfpj-xxrg: It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access
ghsa_unreviewed·2022-04-03·CVSS 6.5
CVE-2021-20295 [MEDIUM] CWE-125 GHSA-rjqx-xfpj-xxrg: It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756, refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.
OSV
qemu vulnerabilities
osv·2020-08-19·CVSS 6.5
CVE-2020-10756 [MEDIUM] qemu vulnerabilities
qemu vulnerabilities
Ziming Zhang and VictorV discovered that the QEMU SLiRP networking
implementation incorrectly handled replying to certain ICMP echo requests.
An attacker inside a guest could possibly use this issue to leak host
memory to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-10756)
Eric Blake and Xueqiang Wei discovered that the QEMU NDB implementation
incorrectly handled certain requests. A remote attacker could possibly use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-10761)
Ziming Zhang discovered that the QEMU SM501 graphics driver incorrectly
handled certain operations. An attacker inside a guest could use this issue
to cause QEMU to crash, resulting in a d
OSV
CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator
osv·2020-07-09·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Microsoft
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to in
vendor_msrc·2022-04-12·CVSS 6.5
CVE-2021-20295 [MEDIUM] CWE-125 It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to in
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756 which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756 refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits t
Debian
CVE-2021-20295: qemu - It was discovered that the update for the virt:rhel module in the RHSA-2020:4676...
vendor_debian·2021·CVSS 6.5
CVE-2021-20295 [MEDIUM] CVE-2021-20295: qemu - It was discovered that the update for the virt:rhel module in the RHSA-2020:4676...
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756, refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2020-08-19·CVSS 6.5
CVE-2020-10756 [MEDIUM] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Ziming Zhang and VictorV discovered that the QEMU SLiRP networking
implementation incorrectly handled replying to certain ICMP echo requests.
An attacker inside a guest could possibly use this issue to leak host
memory to obtain sensitive information. This issue only affected Ubuntu
18.04 LTS. (CVE-2020-10756)
Eric Blake and Xueqiang Wei discovered that the QEMU NDB implementation
incorrectly handled certain requests. A remote attacker could possibly use
this issue to cause QEMU to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-10761)
Ziming Zhang discovered that the QEMU SM501 graphics driver incorrectly
handled certain operations. An attacker inside a guest
Ubuntu
libslirp vulnerability
vendor_ubuntu·2020-07-27
CVE-2020-10756 libslirp vulnerability
Title: libslirp vulnerability
Summary: libslirp could be made to crash if it received specially crafted network
traffic.
Ziming Zhang and VictorV discovered that libslirp incorrectly handled
replying to certain ICMP echo requests. A remote attacker could possibly
use this issue to cause libslirp to crash, resulting in a denial of
service.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
vendor_redhat·2020-05-27·CVSS 6.5
CVE-2020-10756 [MEDIUM] CWE-125 QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible i
Red Hat
QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8.3
vendor_redhat·2020-05-27·CVSS 6.5
CVE-2021-20295 [MEDIUM] CWE-125 QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8.3
QEMU: Regression of CVE-2020-10756 fix in virt:rhel/qemu-kvm in Red Hat Enterprise Linux 8.3
It was discovered that the update for the virt:rhel module in the RHSA-2020:4676 (https://access.redhat.com/errata/RHSA-2020:4676) erratum released as part of Red Hat Enterprise Linux 8.3 failed to include the fix for the qemu-kvm component issue CVE-2020-10756, which was previously corrected in virt:rhel/qemu-kvm via erratum RHSA-2020:4059 (https://access.redhat.com/errata/RHSA-2020:4059). CVE-2021-20295 was assigned to that Red Hat specific security regression. For more details about the original security issue CVE-2020-10756, refer to bug 1835986 or the CVE page: https://access.redhat.com/security/cve/CVE-2020-10756.
It was discovered that the update for the virt:rhel module in the RHSA-2020:4
Debian
CVE-2020-10756: libslirp - An out-of-bounds read vulnerability was found in the SLiRP networking implementa...
vendor_debian·2020·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756: libslirp - An out-of-bounds read vulnerability was found in the SLiRP networking implementa...
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This flaw affects versions of libslirp before 4.3.1.
Scope: local
bookworm: resolved (fixed in 4.3.1-1)
bullseye: resolved (fixed in 4.3.1-1)
forky: resolved (fixed in 4.3.1-1)
sid: resolved (fixed in 4.3.1-1)
trixie: resolved (fixed in 4.3.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [epel-8]
bugzilla·2020-06-01·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [epel-8]
CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the
Bugzilla
CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
bugzilla·2020-06-01·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
CVE-2020-10756 libslirp: QEMU: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2020-10756 qemu: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
bugzilla·2020-06-01·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756 qemu: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
CVE-2020-10756 qemu: slirp: networking out-of-bounds read information disclosure vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2020-10756 QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
bugzilla·2020-05-14·CVSS 6.5
CVE-2020-10756 [MEDIUM] CVE-2020-10756 QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
CVE-2020-10756 QEMU: slirp: networking out-of-bounds read information disclosure vulnerability
An out-of-bounds read vulnerability in function icmp6_send_echoreply() in ip6_icmp.c of libslirp could allow a guest user/process to leak contents of the host memory, leading to possible information disclosure.
Discussion:
OpenShift 4 packages slirp4netns which vendors in libslirp v4.1.0.
Additionally have checked that the code, ip6_icmp.c, does contain the vulnerable memcpy.
---
While processing an incoming ICMPv6 echo request, function icmp6_send_echoreply() does not validate the IPv6 payload length (ip->ip_pl) which is then used as the size of memcpy() to create the destination packet. A malicious user could be able to trick memcpy() into copying more data than allowed, thus potentially
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00040.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1835986https://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYTZ32P67PZER6P7TW6FQK3SZRKQLVEI/https://security.netapp.com/advisory/ntap-20201001-0001/https://usn.ubuntu.com/4437-1/https://usn.ubuntu.com/4467-1/https://www.debian.org/security/2020/dsa-4728https://www.zerodayinitiative.com/advisories/ZDI-20-1005/http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00040.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1835986https://lists.debian.org/debian-lts-announce/2020/07/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYTZ32P67PZER6P7TW6FQK3SZRKQLVEI/https://security.netapp.com/advisory/ntap-20201001-0001/https://usn.ubuntu.com/4437-1/https://usn.ubuntu.com/4467-1/https://www.debian.org/security/2020/dsa-4728https://www.zerodayinitiative.com/advisories/ZDI-20-1005/
2020-07-09
Published