CVE-2020-29129
published 2020-11-26CVE-2020-29129: ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
1.44%
70.3th percentile
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libslirp | < libslirp 4.4.0-1 (bookworm) | libslirp 4.4.0-1 (bookworm) |
| debian | qemu | < libslirp 4.4.0-1 (bookworm) | libslirp 4.4.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libslirp_project | libslirp | <= 4.3.1 | — |
| libslirp_project | libslirp | >= 0 < 4.4.0-1 | 4.4.0-1 |
| libslirp_project | libslirp | >= 0 < 4.4.0-1 | 4.4.0-1 |
| libslirp_project | libslirp | >= 0 < 4.4.0-1 | 4.4.0-1 |
| libslirp_project | libslirp | >= 0 < 4.4.0-1 | 4.4.0-1 |
| libslirp_project | libslirp | >= 0 < 4.1.0-2ubuntu2.2 | 4.1.0-2ubuntu2.2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libslirp vulnerabilities
vendor_ubuntu·2021-10-26·CVSS 4.3
CVE-2021-3593 [MEDIUM] libslirp vulnerabilities
Title: libslirp vulnerabilities
Summary: Several security issues were fixed in libslirp.
USN-5009-1 fixed vulnerabilities in libslirp. This update provides the
corresponding updates for Ubuntu 21.10.
Original advisory details:
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
Instructions: After a standard system update you nee
Ubuntu
libslirp vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 4.3
CVE-2021-3594 [MEDIUM] libslirp vulnerabilities
Title: libslirp vulnerabilities
Summary: Several security issues were fixed in libslirp.
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
vendor_redhat·2020-11-26·CVSS 4.3
CVE-2020-29129 [MEDIUM] CWE-125 QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
QEMU: slirp: out-of-bounds access while processing ARP/NCSI packets
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
An out-of-bounds access issue was found in the SLiRP user networking implementation of QEMU. It could occur while processing ARP/NCSI packets, if the packet length was shorter than required to accommodate respective protocol headers and payload. A privileged guest user may use this flaw to potentially leak host information bytes.
Package: kvm (Red Hat Enterprise Linux 5) - Out of support scope
Package: xen (Red Hat Enterprise Linux 5) - Not affected
Package: qemu-kvm (Red Hat Enterprise Linux 6) - Out of support scope
Package: qemu-kvm (Red Hat Enterprise Linux
Debian
CVE-2020-29129: libslirp - ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read...
vendor_debian·2020·CVSS 4.3
CVE-2020-29129 [MEDIUM] CVE-2020-29129: libslirp - ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read...
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
Scope: local
bookworm: resolved (fixed in 4.4.0-1)
bullseye: resolved (fixed in 4.4.0-1)
forky: resolved (fixed in 4.4.0-1)
sid: resolved (fixed in 4.4.0-1)
trixie: resolved (fixed in 4.4.0-1)
OSV
libslirp vulnerabilities
osv·2021-07-15·CVSS 4.3
CVE-2020-29129 [MEDIUM] libslirp vulnerabilities
libslirp vulnerabilities
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
OSV
CVE-2020-29129: ncsi
osv·2020-11-26·CVSS 4.3
CVE-2020-29129 [MEDIUM] CVE-2020-29129: ncsi
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2020/11/27/1https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45S5IHSWYITJKMRT23HCHJQDI674AMTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPCOHDEONMHH6QPJZKRLLCNRGRYODG7X/https://lists.freedesktop.org/archives/slirp/2020-November/000115.htmlhttp://www.openwall.com/lists/oss-security/2020/11/27/1https://lists.debian.org/debian-lts-announce/2022/09/msg00008.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/45S5IHSWYITJKMRT23HCHJQDI674AMTQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OPCOHDEONMHH6QPJZKRLLCNRGRYODG7X/https://lists.freedesktop.org/archives/slirp/2020-November/000115.html
2020-11-26
Published