#1148836 libslirp: CVE-2026-95508

Package:
src:libslirp
Source:
src:libslirp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 09:51:02 UTC
Severity:
normal
Tags:
#1148836#5
Date:
2026-09-24 07:32:55 UTC
From:
To:
Hi,

The following vulnerability was published for libslirp.

CVE-2026-95508[0]:
| A heap-based buffer overflow was found in the DHCPv6 and TFTP
| response builders of libslirp. When the host is configured with a
| small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP
| blksize option can overflow the reply buffer with attacker-
| controlled content and length, resulting in denial of service and
| potentially arbitrary code execution in the host process. The
| default interface MTU is not affected.

Note the security-tracker references alrady two related commits (I
think we got them right), but is the TFTP part yet missing?


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-95508
https://www.cve.org/CVERecord?id=CVE-2026-95508
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2537748

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148836#10
Date:
2026-09-24 09:49:08 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libslirp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148836@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Tokarev <mjt@tls.msk.ru> (supplier of updated libslirp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 24 Sep 2026 12:38:57 +0300
Source: libslirp
Architecture: source
Version: 4.9.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian QEMU Team <pkg-qemu-devel@lists.alioth.debian.org>
Changed-By: Michael Tokarev <mjt@tls.msk.ru>
Closes: 1148836
Changes:
 libslirp (4.9.5-1) unstable; urgency=medium
 .
   * new upstream release (Closes: #1148836, CVE-2026-95508):
   - Fix bounds-check in processing OEM commands
   - Fix bounds-check in dhcpv6 against MTU
   - Fix blocking sendto on UDP sockets
Checksums-Sha1:
 f43c06650f1c5301bae8a6bdbe4a9d64faee6698 2006 libslirp_4.9.5-1.dsc
 569a38b4d099f2ed436f7c2cef6b88e2c3f02cd3 134635 libslirp_4.9.5.orig.tar.bz2
 fecce018c25c0518285775d83da8ede2057d2a1a 4960 libslirp_4.9.5-1.debian.tar.xz
 3d3c434fd518de4de153d627dfa5b35bd5f2d86c 7456 libslirp_4.9.5-1_source.buildinfo
Checksums-Sha256:
 d3afc86e1dcfc4a21ef986f764a95395f81ea9cc25cbb24a739c7b8f0f8c5233 2006 libslirp_4.9.5-1.dsc
 4f59df896cb345ea76d7f68b1e820872feaa9d8255a6761f6bf8a0f2d5144bcd 134635 libslirp_4.9.5.orig.tar.bz2
 792136e118aaa22212f88eb6870e2fef6e6086599962808813e4770c4d4cc616 4960 libslirp_4.9.5-1.debian.tar.xz
 ae60c8b54d1226f03c9d58f964547ac60b7c758a1045fd41c06fb47801130791 7456 libslirp_4.9.5-1_source.buildinfo
Files:
 4a6954d432f6c781b1ac73693ebdf118 2006 net optional libslirp_4.9.5-1.dsc
 af338ba41803296f2979037b493f6a67 134635 net optional libslirp_4.9.5.orig.tar.bz2
 f57d7e5f374515fbc42945e9c0ce72cb 4960 net optional libslirp_4.9.5-1.debian.tar.xz
 17acb0d3968e5d655f37b49a065a0868 7456 net optional libslirp_4.9.5-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEZKoqtTHVaQM2a/75gqpKJDselHgFAmq07+cACgkQgqpKJDse
lHh6uRAApJfKD/kqfR3cpzpxoPVCg7vf0Ett/TxmOxyMQ6Lc6HLUpjWJLb8NTLEI
+aVCgmp9Z0FRRJ6w8sU3tOrn9tPJM1EZ8oTNbJw86fcTyzl2VZJ4vrfI4IYPnzIy
tTFVCYDbbUXqeU/Rzx1lPxOR83emNZr/hRjTJh9AGILSomqKRmSqiFbmZoUIkVsC
Fx6Oi0FPMUAOSA4DwtYHP+PIk6ZdUiCEBRsCcFyOH5n0PHPIIvetx22ptqxno2dQ
ZaFNWFBOIp/XzJkRPMOtZ9/QhyceXgp+taT6kd05WK1L9l3c5YbbNLc3Zqre+7HO
YFzpCe/UPCFMEi+j3kp4nsLj4LoZo0zS/fp9tGXO2OjijoIgwsDO/WYfUfcgPs1I
sCtr7zLSPfbQXfzSG5pZ2QyfEJfEVHR085yJ91BHP0jb52ODHxHfrbADV4gYYBqt
jqk75wkl3rmRxyTU+kmqCEyraNOJzyN8nQt35dyEhPXXObC7NtObC6b9m9+Jm0HD
u0bpvyaXgu+71UhFWwL62DANnG9/6i52J5mSqhnwIQXMXcpsJCeVqQ7MfQ/2zf9l
YFiPeBd2yK9copdvHHAyzZbRVSRzIG7fw9KARpCQgYIkxL6+Zdq+P5ihGXQqClo9
lmZO4qVQXAkGoEBYkI77phLvzOM0vsxrhKfuWvfQZ/M7LTFfdtU=
=0H/N
-----END PGP SIGNATURE-----