AZL-103472

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103472.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-103472
Upstream
  • CVE-2026-95508
Published
2026-09-22T09:17:06Z
Modified
2026-09-26T05:34:12Z
Summary
CVE-2026-95508 affecting package libslirp 4.9.3-1
Details

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.

References

Affected packages

Azure Linux:3 / libslirp

Package

Name
libslirp
Purl
pkg:rpm/azure-linux/libslirp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.9.3-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103472.json"