First published: Tue Oct 26 2021(Updated: )
USN-5009-1 fixed vulnerabilities in libslirp. This update provides the corresponding updates for Ubuntu 21.10. Original advisory details: Qiuhao Li discovered that libslirp incorrectly handled certain header data lengths. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130) It was discovered that libslirp incorrectly handled certain udp packets. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libslirp0 | <4.4.0-1ubuntu0.21.10.1 | 4.4.0-1ubuntu0.21.10.1 |
Ubuntu Ubuntu | =21.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this advisory is USN-5009-2.
The libslirp0 package with version 4.4.0-1ubuntu0.21.10.1 on Ubuntu 21.10 is affected by this vulnerability.
The severity of this vulnerability is not mentioned in the information provided.
To fix this vulnerability, update the libslirp0 package to version 4.4.0-1ubuntu0.21.10.1 on Ubuntu 21.10.
You can find more information about this vulnerability on the Ubuntu security website using the following references: [CVE-2021-3593](https://ubuntu.com/security/CVE-2021-3593), [CVE-2021-3595](https://ubuntu.com/security/CVE-2021-3595), [CVE-2021-3594](https://ubuntu.com/security/CVE-2021-3594).