In QEMU 3.0.0, tcpemu in slirp/tcpsubr.c has a heap-based buffer overflow.
{ "urgency": "not yet assigned" }