CVE-2026-95508
ADVISORY - nistSummary
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
EPSS Score: 0.00423 (0.363)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Out-of-bounds Write
ADVISORY - redhat
Out-of-bounds Write
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-95508
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
7.4highDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-95508
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Red Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-95508
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)