PT-2026-51663 · Qemu+3 · Qemu+3
CVSS v3.1
6.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
libslirp versions prior to 4.9.2
Description
An integer underflow and out-of-bounds heap read exist in the TCP urgent data handling (sosendoob) within hypervisor host environments, such as QEMU. A privileged attacker in a guest VM (possessing root or
CAP NET RAW privileges) can leak significant amounts of sensitive host-process heap memory by sending crafted TCP segments with manipulated URG flags and urgent pointers ti urp. Real-world incidents have demonstrated that this issue can be chained to achieve arbitrary read and write access on the host.Recommendations
Update libslirp to version 4.9.2 or later.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Qemu
Ubuntu
Libslirp