Out-of-bounds read in libslirp - CVE-2020-29130

 

Out-of-bounds read in libslirp - CVE-2020-29130

Published: November 27, 2020 / Updated: June 22, 2021


Vulnerability identifier: #VU48696
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29130
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to buffer over-read in slirp.c when processing ARP/NCSI packets in 'arp_input' or 'ncsi_input' routines, because the libslirp library tries to read a certain amount of header data even if that exceeds the total packet length. A remote attacker can perform a denial of service attack.


Affected software

libslirp
Arch Linux
SUSE Linux Enterprise Server 15
SUSE Manager Proxy
SUSE Manager Server
SUSE Linux Enterprise Micro
openSUSE Leap Micro
SUSE Enterprise Storage
Fedora
SUSE Linux Enterprise Module for Containers
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
Ubuntu
libslirp (Alpine package)
slirp4netns
slirp4netns-debuginfo
slirp4netns-debugsource
libslirp0 (Ubuntu package)
libslirp

How to mitigate CVE-2020-29130

Install update from vendor's website.

libslirp - update to 4.4.0
libslirp (Alpine package) - update to 4.4.0-r0
slirp4netns - addressed in versions 0.4.7-3.15.1, 0.4.7-150100.3.18.1
slirp4netns-debuginfo - addressed in versions 0.4.7-3.15.1, 0.4.7-150100.3.18.1
slirp4netns-debugsource - addressed in versions 0.4.7-3.15.1, 0.4.7-150100.3.18.1
libslirp0 (Ubuntu package) - addressed in versions 4.1.0-2ubuntu2.2, 4.3.1-1ubuntu0.1, 4.4.0-1ubuntu0.1, 4.4.0-1ubuntu0.21.10.1
libslirp - addressed in versions 4.3.1-2.el8, 4.3.1-3.fc32, 4.3.1-3.fc33

External References

Related Security Bulletins