Impact
A heap‑based buffer overflow was discovered in libslirp’s DHCPv6 and TFTP response builders. The flaw occurs when the host is configured with an interface MTU smaller than the IPv6 minimum link MTU of 1280 bytes; a guest can supply a DHCPv6 CLIENTID option or a TFTP blksize option that overflows the reply buffer with attacker‑controlled content and length. The overflow can lead to denial of service and, if it is successfully exploited, potentially arbitrary code execution in the host process. The likely attack vector is a guest administrator who can craft these DHCPv6 or TFTP packets and send them to the host via the Slirp interface while the host’s MTU is set low.
Affected Systems
The affected products are Red Hat Enterprise Linux 8, 9, 10 and Red Hat OpenShift Container Platform 4. No specific package versions are listed, but any system that loads a vulnerable libslirp build with a small MTU is impacted.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. An EPSS score is not available, so the current exploitation prevalence is unknown. The vulnerability is not listed in the CISA KEV catalog. The overflow is triggered by guest‑supplied network traffic, so an attacker who can control DHCPv6 or TFTP requests to the host and that hosts a small MTU can potentially launch the attack. Successful exploitation would corrupt host memory and could allow code execution, indicating a significant risk to confidentiality, integrity, and availability.
OpenCVE Enrichment