CVE Vulnerabilities

CVE-2019-14378

Improper Handling of Exceptional Conditions

Published: Jul 29, 2019 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
7 IMPORTANT
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
LibslirpLibslirp_project4.0.0 (including)4.0.0 (including)
Advanced Virtualization for RHEL 8.1.0RedHatvirt:8.1-8010020190927171011.cdc1202b*
Advanced Virtualization for RHEL 8.1.0RedHatvirt-devel:8.1-8010020190927171011.cdc1202b*
Red Hat Enterprise Linux 6RedHatqemu-kvm-2:0.12.1.2-2.506.el6_10.6*
Red Hat Enterprise Linux 7RedHatqemu-kvm-ma-10:2.12.0-33.el7_7.1*
Red Hat Enterprise Linux 7RedHatqemu-kvm-10:1.5.3-167.el7_7.4*
Red Hat Enterprise Linux 7.6 Extended Update SupportRedHatqemu-kvm-ma-10:2.12.0-18.el7_6.6*
Red Hat Enterprise Linux 7.6 Extended Update SupportRedHatqemu-kvm-10:1.5.3-160.el7_6.6*
Red Hat Enterprise Linux 7 ExtrasRedHatslirp4netns-0:0.3.0-8.el7_7*
Red Hat Enterprise Linux 8RedHatvirt-devel:rhel-8000020190828150510.f8e95b4e*
Red Hat Enterprise Linux 8RedHatvirt:rhel-8000020190828150510.f8e95b4e*
Red Hat Enterprise Linux 8RedHatcontainer-tools:rhel8-8010020190927090915.4985cc55*
Red Hat Enterprise Linux 8RedHatcontainer-tools:1.0-8010020190927091243.4985cc55*
Red Hat OpenStack Platform 10.0 (Newton)RedHatqemu-kvm-rhev-10:2.12.0-33.el7_7.4*
Red Hat OpenStack Platform 13.0 (Queens)RedHatqemu-kvm-rhev-10:2.12.0-33.el7_7.4*
Red Hat OpenStack Platform 14.0 (Rocky)RedHatqemu-kvm-rhev-10:2.12.0-33.el7_7.4*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatqemu-kvm-rhev-10:2.12.0-33.el7_7.4*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatqemu-kvm-rhev-10:2.12.0-44.el7*
Red Hat Virtualization Engine 4.2RedHatqemu-kvm-rhev-10:2.12.0-18.el7_6.11*
Red Hat Virtualization Engine 4.3RedHatqemu-kvm-rhev-10:2.12.0-33.el7_7.4*
Red Hat Virtualization Engine 4.3RedHatqemu-kvm-rhev-10:2.12.0-44.el7*
AndroidUbuntuesm-apps/xenial*
AndroidUbuntutrusty*
AndroidUbuntuxenial*
Basilisk2Ubuntubionic*
Basilisk2Ubuntudisco*
Basilisk2Ubuntueoan*
Basilisk2Ubuntufocal*
Basilisk2Ubuntugroovy*
Basilisk2Ubuntuhirsute*
Basilisk2Ubuntuimpish*
Basilisk2Ubuntukinetic*
Basilisk2Ubuntulunar*
Basilisk2Ubuntumantic*
Basilisk2Ubuntuoracular*
Basilisk2Ubuntuplucky*
Basilisk2Ubuntutrusty*
Basilisk2Ubuntuxenial*
BochsUbuntubionic*
BochsUbuntudisco*
BochsUbuntueoan*
BochsUbuntufocal*
BochsUbuntugroovy*
BochsUbuntuhirsute*
BochsUbuntuimpish*
BochsUbuntukinetic*
BochsUbuntulunar*
BochsUbuntumantic*
BochsUbuntuoracular*
BochsUbuntuplucky*
BochsUbuntutrusty*
BochsUbuntuxenial*
Fs-uaeUbuntubionic*
Fs-uaeUbuntudisco*
Fs-uaeUbuntueoan*
Fs-uaeUbuntufocal*
Fs-uaeUbuntugroovy*
Fs-uaeUbuntuhirsute*
Fs-uaeUbuntuimpish*
Fs-uaeUbuntukinetic*
Fs-uaeUbuntulunar*
Fs-uaeUbuntumantic*
Fs-uaeUbuntuoracular*
Fs-uaeUbuntuplucky*
Fs-uaeUbuntutrusty*
Fs-uaeUbuntuxenial*
LibslirpUbuntutrusty*
QemuUbuntubionic*
QemuUbuntudevel*
QemuUbuntudisco*
QemuUbuntueoan*
QemuUbuntuesm-infra-legacy/trusty*
QemuUbuntuesm-infra/bionic*
QemuUbuntuesm-infra/focal*
QemuUbuntuesm-infra/xenial*
QemuUbuntufocal*
QemuUbuntugroovy*
QemuUbuntuhirsute*
QemuUbuntuimpish*
QemuUbuntujammy*
QemuUbuntukinetic*
QemuUbuntulunar*
QemuUbuntumantic*
QemuUbuntunoble*
QemuUbuntuoracular*
QemuUbuntuplucky*
QemuUbuntuquesting*
QemuUbuntutrusty*
QemuUbuntutrusty/esm*
QemuUbuntuupstream*
QemuUbuntuxenial*
Qemu-kvmUbuntuprecise/esm*
Qemu-kvmUbuntutrusty*
Qemu-kvm-spiceUbuntutrusty*
Qemu-linaroUbuntutrusty*
SlirpUbuntubionic*
SlirpUbuntudisco*
SlirpUbuntueoan*
SlirpUbuntufocal*
SlirpUbuntugroovy*
SlirpUbuntuhirsute*
SlirpUbuntuimpish*
SlirpUbuntukinetic*
SlirpUbuntulunar*
SlirpUbuntumantic*
SlirpUbuntuoracular*
SlirpUbuntuplucky*
SlirpUbuntutrusty*
SlirpUbuntutrusty/esm*
SlirpUbuntuxenial*
Slirp4netnsUbuntudisco*
Slirp4netnsUbuntutrusty*
Vde2Ubuntubionic*
Vde2Ubuntudisco*
Vde2Ubuntueoan*
Vde2Ubuntufocal*
Vde2Ubuntugroovy*
Vde2Ubuntuhirsute*
Vde2Ubuntuimpish*
Vde2Ubuntukinetic*
Vde2Ubuntulunar*
Vde2Ubuntumantic*
Vde2Ubuntuoracular*
Vde2Ubuntuplucky*
Vde2Ubuntutrusty*
Vde2Ubuntuxenial*
XenUbuntudisco*
XenUbuntueoan*
XenUbuntugroovy*
XenUbuntuhirsute*
XenUbuntuimpish*
XenUbuntutrusty*
XenUbuntuxenial*

References