Description
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Published: 2026-09-22
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Workaround
AI Analysis

Impact

A heap‑based buffer overflow was discovered in libslirp’s DHCPv6 and TFTP response builders. The flaw occurs when the host is configured with an interface MTU smaller than the IPv6 minimum link MTU of 1280 bytes; a guest can supply a DHCPv6 CLIENTID option or a TFTP blksize option that overflows the reply buffer with attacker‑controlled content and length. The overflow can lead to denial of service and, if it is successfully exploited, potentially arbitrary code execution in the host process. The likely attack vector is a guest administrator who can craft these DHCPv6 or TFTP packets and send them to the host via the Slirp interface while the host’s MTU is set low.

Affected Systems

The affected products are Red Hat Enterprise Linux 8, 9, 10 and Red Hat OpenShift Container Platform 4. No specific package versions are listed, but any system that loads a vulnerable libslirp build with a small MTU is impacted.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. An EPSS score is not available, so the current exploitation prevalence is unknown. The vulnerability is not listed in the CISA KEV catalog. The overflow is triggered by guest‑supplied network traffic, so an attacker who can control DHCPv6 or TFTP requests to the host and that hosts a small MTU can potentially launch the attack. Successful exploitation would corrupt host memory and could allow code execution, indicating a significant risk to confidentiality, integrity, and availability.

Generated by OpenCVE AI on September 22, 2026 at 10:23 UTC.

Remediation

Vendor Workaround

Do not configure SlirpConfig.if_mtu below the IPv6 minimum link MTU of 1280.


OpenCVE Recommended Actions

  • Reconfigure Slirp by setting SlirpConfig.if_mtu to at least 1280 to avoid the small‑MTU condition that triggers the overflow.
  • Deploy the vendor‑supplied fix or patch for libslirp as soon as it becomes available; this eliminates the underlying buffer overflow.
  • Verify that all interfaces exposed to guest traffic use the correct minimum MTU and audit configuration files to ensure no accidental reduction below 1280 occurs.

Generated by OpenCVE AI on September 22, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 22 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Title Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-787
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T08:36:01.598Z

Reserved: 2026-09-22T07:22:20.302Z

Link: CVE-2026-95508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T09:17:06.073

Modified: 2026-09-22T09:17:06.073

Link: CVE-2026-95508

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-22T07:27:49Z

Links: CVE-2026-95508 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T10:30:17Z

Weaknesses