CVE-2021-3595
published 2021-06-15CVE-2021-3595: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur…
PriorityP414low3.8CVSS 3.1
AVLACLPRLUINSCCLINAN
EPSS
0.33%
24.7th percentile
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libslirp | < libslirp 4.6.1-1 (bookworm) | libslirp 4.6.1-1 (bookworm) |
| debian | qemu | < libslirp 4.6.1-1 (bookworm) | libslirp 4.6.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libslirp_project | libslirp | < 4.6.0 | 4.6.0 |
| libslirp_project | libslirp | >= 0 < 4.4.0-1+deb11u2 | 4.4.0-1+deb11u2 |
| libslirp_project | libslirp | >= 0 < 4.6.1-1 | 4.6.1-1 |
| libslirp_project | libslirp | >= 0 < 4.6.1-1 | 4.6.1-1 |
| libslirp_project | libslirp | >= 0 < 4.6.1-1 | 4.6.1-1 |
| libslirp_project | libslirp | >= 0 < 4.1.0-2ubuntu2.2 | 4.1.0-2ubuntu2.2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:4.1-2 | 1:4.1-2 |
| qemu | qemu | >= 0 < 1:2.11+dfsg-1ubuntu7.37 | 1:2.11+dfsg-1ubuntu7.37 |
| qemu | qemu | >= 0 < 1:4.2-3ubuntu6.17 | 1:4.2-3ubuntu6.17 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.13.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q3wq-4hwf-24q4: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU
ghsa_unreviewed·2022-05-24
CVE-2021-3595 [LOW] CWE-824 GHSA-q3wq-4hwf-24q4: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
OSV
qemu vulnerabilities
osv·2021-07-15·CVSS 2.3
CVE-2020-15469 [LOW] qemu vulnerabilities
qemu vulnerabilities
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu discovered that QEMU incorrectly handled the virtio-fs shared f
OSV
libslirp vulnerabilities
osv·2021-07-15·CVSS 4.3
CVE-2020-29129 [MEDIUM] libslirp vulnerabilities
libslirp vulnerabilities
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
OSV
CVE-2021-3595: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU
osv·2021-06-15·CVSS 3.8
CVE-2021-3595 [LOW] CVE-2021-3595: An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
Ubuntu
libslirp vulnerabilities
vendor_ubuntu·2021-10-26·CVSS 4.3
CVE-2021-3593 [MEDIUM] libslirp vulnerabilities
Title: libslirp vulnerabilities
Summary: Several security issues were fixed in libslirp.
USN-5009-1 fixed vulnerabilities in libslirp. This update provides the
corresponding updates for Ubuntu 21.10.
Original advisory details:
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
Instructions: After a standard system update you nee
Ubuntu
QEMU vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 2.3
CVE-2021-3594 [LOW] QEMU vulnerabilities
Title: QEMU vulnerabilities
Summary: Several security issues were fixed in QEMU.
Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.
An attacker inside the guest could possibly use this issue to cause QEMU to
crash, resulting in a denial of service. (CVE-2020-15469)
Wenxiang Qian discovered that QEMU incorrectly handled certain ATAPI
commands. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. This issue only
affected Ubuntu 21.04. (CVE-2020-29443)
Cheolwoo Myung discovered that QEMU incorrectly handled SCSI device
emulation. An attacker inside the guest could possibly use this issue to
cause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,
CVE-2020-35505, CVE-2021-3392)
Alex Xu di
Ubuntu
libslirp vulnerabilities
vendor_ubuntu·2021-07-15·CVSS 4.3
CVE-2021-3594 [MEDIUM] libslirp vulnerabilities
Title: libslirp vulnerabilities
Summary: Several security issues were fixed in libslirp.
Qiuhao Li discovered that libslirp incorrectly handled certain header data
lengths. An attacker inside a guest could possibly use this issue to leak
sensitive information from the host. This issue only affected Ubuntu 20.04
LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130)
It was discovered that libslirp incorrectly handled certain udp packets. An
attacker inside a guest could possibly use this issue to leak sensitive
information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594,
CVE-2021-3595)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp)
vendor_redhat·2021-06-14·CVSS 3.8
CVE-2021-3595 [LOW] CWE-824 QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp)
QEMU: slirp: invalid pointer initialization may lead to information disclosure (tftp)
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure.
Debian
CVE-2021-3595: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem...
vendor_debian·2021·CVSS 3.8
CVE-2021-3595 [LOW] CVE-2021-3595: libslirp - An invalid pointer initialization issue was found in the SLiRP networking implem...
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
Scope: local
bookworm: resolved (fixed in 4.6.1-1)
bullseye: resolved (fixed in 4.4.0-1+deb11u2)
forky: resolved (fixed in 4.6.1-1)
sid: resolved (fixed in 4.6.1-1)
trixie: resolved (fixed in 4.6.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1970489https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCKWZWY64EHTOQMLVLTSZ4AA27EWRJMH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGPQZFVJCFGDSISFXPCQTTBBD7QZLJKI/https://security.gentoo.org/glsa/202107-44https://security.netapp.com/advisory/ntap-20210805-0004/https://bugzilla.redhat.com/show_bug.cgi?id=1970489https://lists.debian.org/debian-lts-announce/2021/09/msg00000.htmlhttps://lists.debian.org/debian-lts-announce/2023/03/msg00013.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GCKWZWY64EHTOQMLVLTSZ4AA27EWRJMH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGPQZFVJCFGDSISFXPCQTTBBD7QZLJKI/https://security.gentoo.org/glsa/202107-44https://security.netapp.com/advisory/ntap-20210805-0004/
2021-06-15
Published