#VU54308 Release of invalid pointer or reference in libslirp - CVE-2021-3592
Published: June 22, 2021
libslirp
Freedesktop.org
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to invalid pointer initialization within the bootp_input() function while processing UDP packets in the SLiRP networking implementation of QEMU. A malicious guest could use this flaw to leak 10 bytes of uninitialized heap memory from the host.