SB2022083017 - SUSE update for libslirp
Published: August 30, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Release of invalid pointer or reference (CVE-ID: CVE-2021-3593)
The vulnerability allows a remote attacker to gain access to sensitive information.
The
vulnerability exists due to invalid pointer initialization within the udp6_input() function while processing UDP packets in the SLiRP
networking implementation of QEMU. A malicious guest could use this vulnerability to read host memory.
Remediation
Install update from vendor's website.