An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory disclosure to the guest. The highest threat from this vulnerability is to data confidentiality. This flaw affects libslirp versions prior to 4.6.0.
                
            References
                    | Link | Resource | 
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1970491 | Issue Tracking Patch Third Party Advisory | 
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SGPQZFVJCFGDSISFXPCQTTBBD7QZLJKI/ | Mailing List Third Party Advisory | 
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCKWZWY64EHTOQMLVLTSZ4AA27EWRJMH/ | Mailing List Third Party Advisory | 
| https://security.gentoo.org/glsa/202107-44 | Third Party Advisory | 
| https://security.netapp.com/advisory/ntap-20210805-0004/ | Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2021/09/msg00000.html | Mailing List Third Party Advisory | 
| https://lists.debian.org/debian-lts-announce/2023/03/msg00013.html | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
Configuration 3 (hide)
| 
 | 
Configuration 4 (hide)
| 
 | 
Information
                Published : 2021-06-15 14:15
Updated : 2023-03-14 17:15
NVD link : CVE-2021-3594
Mitre link : CVE-2021-3594
JSON object : View
CWE
                No CWE.
Products Affected
                debian
- debian_linux
fedoraproject
- fedora
redhat
- enterprise_linux
libslirp_project
- libslirp


