Heap-Based Buffer Overflow in libslirp Affects Multiple Products
CVE-2026-95508
7.4HIGH
What is CVE-2026-95508?
A heap-based buffer overflow vulnerability exists in the DHCPv6 and TFTP response builders of libslirp. When the host operates with a small interface Maximum Transmission Unit (MTU) setting, an attacker can exploit this weakness by supplying a malicious DHCPv6 CLIENTID option or TFTP block size option. This can lead to overflowing the reply buffer with injected content, potentially resulting in denial of service and allowing arbitrary code execution within the host process. Notably, the default interface MTU is not impacted, positioning systems with adjusted configurations at risk.
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Stuart Thomas for reporting this issue.