USN-5009-2: libslirp vulnerabilities
USN-5009-1 fixed vulnerabilities in libslirp. This update provides the corresponding updates for Ubuntu 21.10. Original advisory details: Qiuhao Li discovered that libslirp incorrectly handled certain header data lengths. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-29129, CVE-2020-29130) It was discovered that libslirp incorrectly handled certain udp packets. An attacker inside a guest could possibly use this issue to leak sensitive information from the host. (CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-5009-2.
What software is affected by this vulnerability?
The libslirp0 package with version 4.4.0-1ubuntu0.21.10.1 on Ubuntu 21.10 is affected by this vulnerability.
What is the severity of this vulnerability?
The severity of this vulnerability is not mentioned in the information provided.
How can I fix this vulnerability?
To fix this vulnerability, update the libslirp0 package to version 4.4.0-1ubuntu0.21.10.1 on Ubuntu 21.10.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu security website using the following references: [CVE-2021-3593](https://ubuntu.com/security/CVE-2021-3593), [CVE-2021-3595](https://ubuntu.com/security/CVE-2021-3595), [CVE-2021-3594](https://ubuntu.com/security/CVE-2021-3594).