We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
https://security-tracker.debian.org/tracker/CVE-2019-15890
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
On upstream libslirp, the vulnerability was fixed on Aug 26, 2019: https://gitlab.freedesktop.org/slirp/libslirp/commit/c59279437eda91841b9d26079c70b8a540d41204
The fix was to applied to slirp4netns in:
Impact
https://security-tracker.debian.org/tracker/CVE-2019-15890
Patches
On upstream libslirp, the vulnerability was fixed on Aug 26, 2019: https://gitlab.freedesktop.org/slirp/libslirp/commit/c59279437eda91841b9d26079c70b8a540d41204
The fix was to applied to slirp4netns in: