Out-of-bounds read in libslirp - CVE-2020-10756

 

Out-of-bounds read in libslirp - CVE-2020-10756

Published: July 22, 2020 / Updated: August 17, 2020


Vulnerability identifier: #VU31746
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-10756
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in the "icmp6_send_echoreply()" routine while replying to an ICMP echo request. A remote attacker with access to guest operating system can trigger out-of-bounds read error and read contents of memory on the system.


Affected software

libslirp
Debian Linux
Red Hat CodeReady Linux Builder for ARM 64
Fedora
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu
libslirp (Alpine package)
qemu-system (Ubuntu package)
qemu-system-ppc (Ubuntu package)
qemu-system-mips (Ubuntu package)
qemu-system-s390x (Ubuntu package)
qemu-system-arm (Ubuntu package)
qemu-system-sparc (Ubuntu package)
qemu (Ubuntu package)
qemu-system-x86 (Ubuntu package)
qemu-system-aarch64 (Ubuntu package)
qemu (Debian package)
libslirp0 (Ubuntu package)
qemu-system-x86-microvm (Ubuntu package)
qemu-system-x86-xen (Ubuntu package)
libslirp
Red Hat Enterprise Linux Advanced Virtualization

How to mitigate CVE-2020-10756

Install updates from vendor's website.

libslirp - update to 4.3.1
libslirp (Alpine package) - update to 4.3.1-r0
qemu-system (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-ppc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-mips (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-s390x (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-arm (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:4.2-3ubuntu6.4
qemu-system-sparc (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-x86 (Ubuntu package) - addressed in versions 1:2.5+dfsg-5ubuntu10.45, 1:2.11+dfsg-1ubuntu7.31, 1:4.2-3ubuntu6.4
qemu-system-aarch64 (Ubuntu package) - update to 1:2.5+dfsg-5ubuntu10.45
qemu (Debian package) - update to 1:3.1+dfsg-8+deb10u6
libslirp0 (Ubuntu package) - update to 4.1.0-2ubuntu2.1
qemu-system-x86-microvm (Ubuntu package) - update to 1:4.2-3ubuntu6.4
qemu-system-x86-xen (Ubuntu package) - update to 1:4.2-3ubuntu6.4
libslirp - addressed in versions 4.3.1-1.el8, 4.3.1-1.fc32

External References

Related Security Bulletins