Libslirp is a lightweight user-mode network stack library widely embedded in virtualization platforms and emulators to provide network connectivity without kernel involvement. The vendor's vulnerability profile centers on a single library product and recurs through memory-safety weakness classes including buffer overflows, out-of-bounds reads and writes, use-after-free conditions, and uninitialized-pointer access, reflecting the low-level packet-handling code that sits at the core of the component. A moderate share of disclosures have acquired public exploit code, and defenders should treat this library as a supply-chain dependency requiring careful inventory in hypervisor and emulation software; current exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libslirp Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14378HIGH ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment. | Jul 29, 2019 | 8.8 | 48 | NO | YES |
CVE-2019-15890HIGH libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c. | Sep 6, 2019 | 7.5 | 26 | NO | NO |
CVE-2020-7211HIGH tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | Jan 21, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-8608MEDIUM In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code. | Feb 6, 2020 | 5.6 | 22 | NO | NO |
CVE-2020-7039MEDIUM tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or ot | Jan 16, 2020 | 5.6 | 22 | NO | NO |
CVE-2020-1983MEDIUM A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. | Apr 22, 2020 | 6.5 | 20 | NO | NO |
CVE-2020-29130MEDIUM slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. | Nov 26, 2020 | 4.3 | 18 | NO | NO |
CVE-2020-29129MEDIUM ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. | Nov 26, 2020 | 4.3 | 18 | NO | NO |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a ud | Jun 15, 2021 | 3.8 | 17 | NO | NO |
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp | Jun 15, 2021 | 3.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libslirp Project.
Media articles that mention a CVE ID that affects a product developed by Libslirp Project — matched by CVE ID, not by vendor name.