cbcvebase.
CVE-2021-3594
published 2021-06-15

CVE-2021-3594: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur…

PriorityP414low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.33%
24.8th percentile
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.

Affected

24 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibslirp< libslirp 4.6.1-1 (bookworm)libslirp 4.6.1-1 (bookworm)
debianqemu< libslirp 4.6.1-1 (bookworm)libslirp 4.6.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
libslirp_projectlibslirp< 4.6.04.6.0
libslirp_projectlibslirp>= 0 < 4.4.0-1+deb11u24.4.0-1+deb11u2
libslirp_projectlibslirp>= 0 < 4.6.1-14.6.1-1
libslirp_projectlibslirp>= 0 < 4.6.1-14.6.1-1
libslirp_projectlibslirp>= 0 < 4.6.1-14.6.1-1
libslirp_projectlibslirp>= 0 < 4.1.0-2ubuntu2.24.1.0-2ubuntu2.2
qemuqemu>= 0 < 1:4.1-21:4.1-2
qemuqemu>= 0 < 1:4.1-21:4.1-2
qemuqemu>= 0 < 1:4.1-21:4.1-2
qemuqemu>= 0 < 1:4.1-21:4.1-2
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.371:2.11+dfsg-1ubuntu7.37
qemuqemu>= 0 < 1:4.2-3ubuntu6.171:4.2-3ubuntu6.17
qemuqemu>= 0 < 1:4.2-3ubuntu6.301:4.2-3ubuntu6.30
qemuqemu>= 0 < 1:6.2+dfsg-2ubuntu6.241:6.2+dfsg-2ubuntu6.24
qemuqemu>= 0 < 1:8.2.2+ds-0ubuntu1.41:8.2.2+ds-0ubuntu1.4
qemuqemu>= 0 < 2.0.0+dfsg-2ubuntu1.47+esm42.0.0+dfsg-2ubuntu1.47+esm4
qemuqemu>= 0 < 1:2.5+dfsg-5ubuntu10.51+esm31:2.5+dfsg-5ubuntu10.51+esm3
qemuqemu>= 0 < 1:2.11+dfsg-1ubuntu7.42+esm21:2.11+dfsg-1ubuntu7.42+esm2
redhatenterprise_linux

CVSS provenance

nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.