Bug 26588

Summary: libslirp/slirp4netns new security issue CVE-2020-1983
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Joseph Wang <joequant>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: geiger.david68210
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: libslirp-4.2.0-1.mga8.src.rpm, slirp4netns-0.4.4-1.mga8.src.rpm CVE:
Status comment:

Comment 1 David GEIGER 2020-05-05 10:37:13 CEST
Done for Cauldron!

CC: (none) => geiger.david68210

Comment 2 David Walser 2020-05-05 16:03:38 CEST
Fixed in libslirp-4.2.0-2.mga8.

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 3 David Walser 2020-05-06 20:38:59 CEST
SUSE has issued an advisory toay (May 6):
http://lists.suse.com/pipermail/sle-security-updates/2020-May/006785.html

The slirp4netns package is also affected.

I'm not sure if they just upgraded to 0.4.5 or if it needed to be patched.

Status: RESOLVED => REOPENED
Source RPM: libslirp-4.2.0-1.mga8.src.rpm => libslirp-4.2.0-1.mga8.src.rpm, slirp4netns-0.4.4-1.mga8.src.rpm
Assignee: thierry.vignaud => joequant
Resolution: FIXED => (none)
Summary: libslirp new security issue CVE-2020-1983 => libslirp/slirp4netns new security issue CVE-2020-1983

Comment 4 David Walser 2020-05-11 22:48:42 CEST
(In reply to David Walser from comment #3)
> SUSE has issued an advisory today (May 6):
> http://lists.suse.com/pipermail/sle-security-updates/2020-May/006785.html
> 
> The slirp4netns package is also affected.
> 
> I'm not sure if they just upgraded to 0.4.5 or if it needed to be patched.

openSUSE has issued an advisory for this today (May 11):
https://lists.opensuse.org/opensuse-updates/2020-05/msg00065.html

They only needed to update to 0.4.5.
Comment 5 David GEIGER 2020-05-12 07:35:23 CEST
Latest release 1.0.1 uses now system libslirp.
Comment 6 David Walser 2020-05-12 14:30:53 CEST
OK, that's good.  It hasn't been pushed yet.
Comment 7 David GEIGER 2020-05-12 15:34:42 CEST
So fixed for Cauldron updating slirp4netns to latest 1.0.1 release that uses now system libslirp.
Comment 8 David Walser 2020-05-12 15:41:05 CEST
Fixed in slirp4netns-1.0.1-1.mga8.  Thanks!

Resolution: (none) => FIXED
Status: REOPENED => RESOLVED