We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
https://security-tracker.debian.org/tracker/CVE-2020-8608
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
slirp4netns v0.3.2, 0.4.0-beta.3, and later versions are not affected because tcp_emu is disabled:
tcp_emu
8c4db8e#diff-6ca387a3a00bdc638c01a82f8200db0fR106
3f9e646#diff-6ca387a3a00bdc638c01a82f8200db0fR106
Impact
https://security-tracker.debian.org/tracker/CVE-2020-8608
Patches
slirp4netns v0.3.2, 0.4.0-beta.3, and later versions are not affected because
tcp_emu
is disabled:8c4db8e#diff-6ca387a3a00bdc638c01a82f8200db0fR106
3f9e646#diff-6ca387a3a00bdc638c01a82f8200db0fR106