Bug 26963 - libslirp new security issue CVE-2020-10756
Summary: libslirp new security issue CVE-2020-10756
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Mageia Bug Squad
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-07-16 23:56 CEST by David Walser
Modified: 2020-07-17 12:31 CEST (History)
1 user (show)

See Also:
Source RPM: libslirp-4.2.0-2.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-07-16 23:56:09 CEST
Upstream has issued an advisory on July 8:
https://github.com/rootless-containers/slirp4netns/security/advisories/GHSA-96c5-v27g-58vf

The issue is fixed upstream in 4.3.1.

More info on SUSE and RedHat bugs:
https://bugzilla.suse.com/show_bug.cgi?id=1172380
https://bugzilla.redhat.com/show_bug.cgi?id=1835986
Comment 1 David Walser 2020-07-17 00:25:16 CEST
Fedora has issued an advisory for this on July 15:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JYTZ32P67PZER6P7TW6FQK3SZRKQLVEI/

BTW, slirp4netns has a broken version in Cauldron (IPv6 specifically) so it should be updated to the latest.
Comment 2 David GEIGER 2020-07-17 10:52:09 CEST
Done! closed this bug.

Status: NEW => RESOLVED
Resolution: (none) => FIXED
CC: (none) => geiger.david68210

Comment 3 David Walser 2020-07-17 12:31:25 CEST
libslirp-4.3.1-1.mga8
slirp4netns-1.1.4-1.mga8

Note You need to log in before you can comment on or make changes to this bug.