CVE-2020-10756: QEMU SLiRP Networking Out-Of-Bounds Read Information Disclosure Vulnerability
An out-of-bounds read vulnerability in function icmp6sendechoreply() in ip6icmp.c of libslirp could allow a guest user/process to leak contents of the host memory, leading to possible information disclosure.
Other sources
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6sendechoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1+deb11u2Fixed in 4.7.0-1Fixed in 4.8.0-1 - Upgrade
Upgrade
debian/qemuto a version that resolves this vulnerability.Fixed in 1:5.2+dfsg-11+deb11u3Fixed in 1:5.2+dfsg-11+deb11u2Fixed in 1:7.2+dfsg-7+deb12u12Fixed in 1:10.0.0~rc3+ds-2 - Upgrade
Upgrade
debian/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.0.1-2Fixed in 1.2.0-1Fixed in 1.2.1-1Fixed in 1.2.1-1.1 - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.3.1 - Upgrade
Upgrade
libslirp (QEMU SLiRP networking)to a version that resolves this vulnerability.Fixed in 4.3.1 - Compensating control
Treat QEMU SLiRP networking as untrusted in multi-tenant or attacker-controlled guest scenarios; restrict or isolate guests so untrusted guest users/processes cannot exploit SLiRP to leak host memory or gain further leverage.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-10756?
CVE-2020-10756 is a vulnerability that allows local attackers to execute arbitrary code on affected installations of QEMU.
How can an attacker exploit CVE-2020-10756?
An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability.
Which software versions are affected by CVE-2020-10756?
The affected software versions include Libslirp Project Libslirp 4.3.1, Redhat Openstack 13, Redhat Enterprise Linux 7.0 and 8.0, Canonical Ubuntu Linux 16.04, 18.04, and 20.04, Debian Debian Linux 9.0 and 10.0, and openSUSE Leap 15.0 and 15.1.
What is the severity of CVE-2020-10756?
The severity of CVE-2020-10756 is medium with a CVSS score of 6.5.
How do I fix CVE-2020-10756?
To fix CVE-2020-10756, update to the latest version of the affected software or apply the necessary patches provided by the vendors.