Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2026-95507

Medium priority
Needs evaluation

[Unknown description]

1 affected package

libslirp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-95508

Medium priority
Needs evaluation

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the...

1 affected package

libslirp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-9539

Medium priority

Some fixes available 3 of 5

An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker...

1 affected package

libslirp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Fixed Fixed Fixed Needs evaluation —
Show less packages

CVE-2021-3595

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp — Fixed Fixed Fixed Not in release
qemu — Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3594

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp — Fixed Fixed Fixed Not in release
qemu — Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3593

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Fixed Fixed Fixed Fixed Not in release
qemu Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2021-3592

Low priority
Fixed

An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the...

2 affected packages

libslirp, qemu

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp — Fixed Fixed Fixed Not in release
qemu — Not affected Not affected Not affected Fixed
Show less packages

CVE-2020-29130

Low priority
Fixed

slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

3 affected packages

libslirp, qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp — — Not affected Fixed Not in release
qemu — — Not affected Not affected Not affected
qemu-kvm — — Not in release Not in release Not in release
Show less packages

CVE-2020-29129

Low priority
Fixed

ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

3 affected packages

libslirp, qemu, qemu-kvm

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp — Not affected Not affected Fixed Not in release
qemu — Not affected Not affected Not affected Not affected
qemu-kvm — Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-10756

Medium priority

Some fixes available 2 of 5

An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This...

4 affected packages

libslirp, qemu, qemu-kvm, slirp4netns

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libslirp Not affected Not affected Not affected Fixed Not in release
qemu Not affected Not affected Not affected Not affected Fixed
qemu-kvm Not in release Not in release Not in release Not in release Not in release
slirp4netns Not affected Not affected Not affected Vulnerable Not in release
Show less packages