Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libslirp for openSUSE:Factory checked in at 2026-09-29 17:46:44 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libslirp (Old) and /work/SRC/openSUSE:Factory/.libslirp.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libslirp" Tue Sep 29 17:46:44 2026 rev:15 rq:1381144 version:4.9.5+1 Changes: -------- --- /work/SRC/openSUSE:Factory/libslirp/libslirp.changes 2026-06-27 18:03:50.243423169 +0200 +++ /work/SRC/openSUSE:Factory/.libslirp.new.383539/libslirp.changes 2026-09-29 17:47:40.432937087 +0200 @@ -1,0 +2,17 @@ +Fri Sep 25 13:51:58 UTC 2026 - Petr Gajdos <[email protected]> + gemini + +- Update to version 4.9.5+1: + * note CVE numbers + * Release v4.9.5 + * Set UDP sockets in blocking mode + * dhcpv6: fix bounding the reply against the interface MTU + * dhcpv6: bound the reply against the interface MTU + * ncsi: bounds-check OEM command bodies before dereferencing them + * Release v4.9.4 + * ip_input: update hlen on ip_reass + * ip6_input: Trim mbuf to ip6-announced length + * Fix reporting oob output + * Note about the security contact +- fixes CVE-2026-95507, CVE-2026-95508 + +------------------------------------------------------------------- Old: ---- libslirp-4.9.3+4.obscpio New: ---- libslirp-4.9.5+1.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libslirp.spec ++++++ --- /var/tmp/diff_new_pack.LQE1va/_old 2026-09-29 17:47:42.994044229 +0200 +++ /var/tmp/diff_new_pack.LQE1va/_new 2026-09-29 17:47:42.996044312 +0200 @@ -19,7 +19,7 @@ %define libname libslirp0 Name: libslirp -Version: 4.9.3+4 +Version: 4.9.5+1 Release: 0 Summary: A general purpose TCP-IP emulator License: MIT ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.LQE1va/_old 2026-09-29 17:47:43.043046279 +0200 +++ /var/tmp/diff_new_pack.LQE1va/_new 2026-09-29 17:47:43.046046404 +0200 @@ -1,6 +1,6 @@ <servicedata> <service name="tar_scm"> <param name="url">https://gitlab.freedesktop.org/slirp/libslirp.git</param> - <param name="changesrevision">d82ac5a853813d70cb990bc31d6faeffe8e4dc51</param></service></servicedata> + <param name="changesrevision">62b298621dfc413a42d2181933f5335815afa1a4</param></service></servicedata> (No newline at EOF) ++++++ libslirp-4.9.3+4.obscpio -> libslirp-4.9.5+1.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/CHANGELOG.md new/libslirp-4.9.5+1/CHANGELOG.md --- old/libslirp-4.9.3+4/CHANGELOG.md 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/CHANGELOG.md 2026-09-22 23:06:37.000000000 +0200 @@ -5,6 +5,32 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [4.9.5] - 2026-09-22 + +## Security + + - Fix bounds-check in processing OEM commands (CVE-2026-95507) + - Fix bounds-check in dhcpv6 against MTU (CVE-2026-95508) + +### Fixed + + - Fix blocking sendto on UDP ockets #97 + +## [4.9.4] - 2026-08-25 + +## Security + + - Fix information leak on fragmented packets with different header lengths + +### Fixed + + - Fix reporting oob output #95 + - Fix buffer trimming to ip6-announced length #96 + +## Changed + + - slirp: permit guestfwd to vhost_addr/vnameserver_addr #81 #140 + ## [4.9.3] - 2026-05-26 ### Fixed @@ -289,7 +315,9 @@ - Standalone project, removing any QEMU dependency. - License clarifications. -[Unreleased]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.3...master +[Unreleased]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.5...master +[4.9.5]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.4...v4.9.5 +[4.9.4]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.3...v4.9.4 [4.9.3]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.2...v4.9.3 [4.9.2]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.1...v4.9.2 [4.9.1]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.0...v4.9.1 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/README.md new/libslirp-4.9.5+1/README.md --- old/libslirp-4.9.3+4/README.md 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/README.md 2026-09-22 23:06:37.000000000 +0200 @@ -45,6 +45,10 @@ Alternatively, you may send patches to [email protected] mailing list. +Security reports can be sent to [email protected] +with pgp key 900CB024B67931D40F82304BD0178C767D069EE6 (it can be found +in the debian keyring for instance) + ## Debugging To make slirp emit debugging prints, one can use for instance: diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/meson.build new/libslirp-4.9.5+1/meson.build --- old/libslirp-4.9.3+4/meson.build 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/meson.build 2026-09-22 23:06:37.000000000 +0200 @@ -1,5 +1,5 @@ project('libslirp', 'c', - version : '4.9.3', + version : '4.9.5', license : 'BSD-3-Clause', default_options : ['warning_level=1', 'c_std=gnu99'], meson_version : '>= 0.60', diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/dhcpv6.c new/libslirp-4.9.5+1/src/dhcpv6.c --- old/libslirp-4.9.3+4/src/dhcpv6.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/dhcpv6.c 2026-09-22 23:06:37.000000000 +0200 @@ -157,6 +157,11 @@ *resp++ = (uint8_t)xid; if (ri.client_id) { + if (resp + 4 + ri.client_id_len > + (uint8_t *)m->m_data + slirp->if_mtu) { + m_free(m); /* response would overflow the interface-MTU-sized mbuf */ + return; + } *resp++ = OPTION_CLIENTID >> 8; /* option-code high byte */ *resp++ = OPTION_CLIENTID; /* option-code low byte */ *resp++ = ri.client_id_len >> 8; /* option-len high byte */ @@ -165,6 +170,10 @@ resp += ri.client_id_len; } if (ri.want_dns) { + if (resp + 4 + 16 > (uint8_t *)m->m_data + slirp->if_mtu) { + m_free(m); /* reply would not fit the interface-MTU-sized mbuf */ + return; + } *resp++ = OPTION_DNS_SERVERS >> 8; /* option-code high byte */ *resp++ = OPTION_DNS_SERVERS; /* option-code low byte */ *resp++ = 0; /* option-len high byte */ @@ -176,9 +185,14 @@ uint8_t *sa = slirp->vhost_addr6.s6_addr; int slen, smaxlen; + smaxlen = (uint8_t *)m->m_data + slirp->if_mtu - (resp + 4); + if (smaxlen < 0) { + m_free(m); /* boot-url would not fit the interface-MTU-sized mbuf */ + return; + } + *resp++ = OPTION_BOOTFILE_URL >> 8; /* option-code high byte */ *resp++ = OPTION_BOOTFILE_URL; /* option-code low byte */ - smaxlen = (uint8_t *)m->m_data + slirp->if_mtu - (resp + 2); slen = slirp_fmt((char *)resp + 2, smaxlen, "tftp://[%02x%02x:%02x%02x:%02x%02x:%02x%02x:" "%02x%02x:%02x%02x:%02x%02x:%02x%02x]/%s", diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/ip6_input.c new/libslirp-4.9.5+1/src/ip6_input.c --- old/libslirp-4.9.3+4/src/ip6_input.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/ip6_input.c 2026-09-22 23:06:37.000000000 +0200 @@ -28,6 +28,7 @@ M_DUP_DEBUG(slirp, m, 1, TCPIPHDR_DELTA + 2 + ETH_HLEN); struct ip6 *ip6; + int ip6_len; if (!slirp->in6_enabled) { goto bad; @@ -47,7 +48,9 @@ goto bad; } - if (ntohs(ip6->ip_pl) + sizeof(struct ip6) > slirp->if_mtu) { + ip6_len = ntohs(ip6->ip_pl) + sizeof(struct ip6); + + if (ip6_len > slirp->if_mtu) { icmp6_send_error(m, ICMP6_TOOBIG, 0); goto bad; } @@ -55,10 +58,14 @@ // Check if the message size is big enough to hold what's // set in the payload length header. If not this is an invalid // packet - if (m->m_len < ntohs(ip6->ip_pl) + sizeof(struct ip6)) { + if (m->m_len < ip6_len) { goto bad; } + /* Should drop packet if mbuf too long? hmmm... */ + if (m->m_len > ip6_len) + m_adj(m, ip6_len - m->m_len); + /* check ip_ttl for a correct ICMP reply */ if (ip6->ip_hl == 0) { icmp6_send_error(m, ICMP6_TIMXCEED, ICMP6_TIMXCEED_INTRANS); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/ip_input.c new/libslirp-4.9.5+1/src/ip_input.c --- old/libslirp-4.9.3+4/src/ip_input.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/ip_input.c 2026-09-22 23:06:37.000000000 +0200 @@ -187,6 +187,7 @@ if (ip == NULL) return; m = dtom(slirp, ip); + hlen = ip->ip_hl << 2; } else if (q) ip_freef(slirp, q); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/ncsi.c new/libslirp-4.9.5+1/src/ncsi.c --- old/libslirp-4.9.3+4/src/ncsi.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/ncsi.c 2026-09-22 23:06:37.000000000 +0200 @@ -58,7 +58,7 @@ /* Response handler for Mellanox command Get Mac Address */ static int ncsi_rsp_handler_oem_mlx_gma(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { uint8_t oob_eth_addr_allocated = 0; struct ncsi_rsp_oem_pkt *rsp; @@ -85,7 +85,7 @@ /* Response handler for Mellanox card */ static int ncsi_rsp_handler_oem_mlx(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { const struct ncsi_cmd_oem_pkt *cmd; const struct ncsi_rsp_oem_mlx_pkt *cmd_mlx; @@ -100,6 +100,14 @@ rsp = (struct ncsi_rsp_oem_pkt *)rnh; rsp_mlx = (struct ncsi_rsp_oem_mlx_pkt *)rsp->data; + if (pkt_len < ETH_HLEN + sizeof(struct ncsi_cmd_oem_pkt) + + sizeof(struct ncsi_rsp_oem_mlx_pkt)) { + rsp->rsp.common.length = htons(8); + rsp->rsp.code = htons(NCSI_PKT_RSP_C_UNSUPPORTED); + rsp->rsp.reason = htons(NCSI_PKT_RSP_R_UNKNOWN); + return -ENOENT; + } + /* Ensure the OEM response header matches the command's */ rsp_mlx->cmd_rev = cmd_mlx->cmd_rev; rsp_mlx->cmd = cmd_mlx->cmd; @@ -108,7 +116,7 @@ if (cmd_mlx->cmd == NCSI_OEM_MLX_CMD_GMA && cmd_mlx->param == NCSI_OEM_MLX_CMD_GMA_PARAM) - return ncsi_rsp_handler_oem_mlx_gma(slirp, nh, rnh); + return ncsi_rsp_handler_oem_mlx_gma(slirp, nh, rnh, pkt_len); rsp->rsp.common.length = htons(8); rsp->rsp.code = htons(NCSI_PKT_RSP_C_UNSUPPORTED); @@ -119,7 +127,7 @@ static const struct ncsi_rsp_oem_handler { unsigned int mfr_id; int (*handler)(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh); + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len); } ncsi_rsp_oem_handlers[] = { { NCSI_OEM_MFR_MLX_ID, ncsi_rsp_handler_oem_mlx }, { NCSI_OEM_MFR_BCM_ID, NULL }, @@ -128,14 +136,18 @@ /* Response handler for OEM command */ static int ncsi_rsp_handler_oem(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { const struct ncsi_rsp_oem_handler *nrh = NULL; const struct ncsi_cmd_oem_pkt *cmd = (const struct ncsi_cmd_oem_pkt *)nh; struct ncsi_rsp_oem_pkt *rsp = (struct ncsi_rsp_oem_pkt *)rnh; - uint32_t mfr_id = ntohl(cmd->mfr_id); + uint32_t mfr_id; int i; + if (pkt_len < ETH_HLEN + sizeof(struct ncsi_cmd_oem_pkt)) { + goto error; + } + mfr_id = ntohl(cmd->mfr_id); rsp->mfr_id = cmd->mfr_id; if (mfr_id != slirp->mfr_id) { @@ -159,7 +171,7 @@ } /* Process the packet */ - return nrh->handler(slirp, nh, rnh); + return nrh->handler(slirp, nh, rnh, pkt_len); error: rsp->rsp.common.length = htons(8); @@ -171,7 +183,7 @@ /* Get Version ID */ static int ncsi_rsp_handler_gvi(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { struct ncsi_rsp_gvi_pkt *rsp = (struct ncsi_rsp_gvi_pkt *)rnh; @@ -183,7 +195,7 @@ /* Get Capabilities */ static int ncsi_rsp_handler_gc(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { struct ncsi_rsp_gc_pkt *rsp = (struct ncsi_rsp_gc_pkt *)rnh; @@ -199,7 +211,7 @@ /* Get Link status */ static int ncsi_rsp_handler_gls(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { struct ncsi_rsp_gls_pkt *rsp = (struct ncsi_rsp_gls_pkt *)rnh; @@ -209,7 +221,7 @@ /* Get Parameters */ static int ncsi_rsp_handler_gp(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh) + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len) { struct ncsi_rsp_gp_pkt *rsp = (struct ncsi_rsp_gp_pkt *)rnh; @@ -226,7 +238,7 @@ unsigned char type; int payload; int (*handler)(Slirp *slirp, const struct ncsi_pkt_hdr *nh, - struct ncsi_rsp_pkt_hdr *rnh); + struct ncsi_rsp_pkt_hdr *rnh, int pkt_len); } ncsi_rsp_handlers[] = { { NCSI_PKT_RSP_CIS, 4, NULL }, /* Clear Initial State */ { NCSI_PKT_RSP_SP, 4, NULL }, /* Select Package */ { NCSI_PKT_RSP_DP, 4, NULL }, /* Deselect Package */ @@ -313,7 +325,7 @@ rnh->reason = htons(NCSI_PKT_RSP_R_NO_ERROR); if (handler->handler) { - handler->handler(slirp, nh, rnh); + handler->handler(slirp, nh, rnh, pkt_len); } ncsi_rsp_len += ntohs(rnh->common.length); } else { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/socket.c new/libslirp-4.9.5+1/src/socket.c --- old/libslirp-4.9.3+4/src/socket.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/socket.c 2026-09-22 23:06:37.000000000 +0200 @@ -418,7 +418,7 @@ if (so->so_urgc) { uint32_t expected = so->so_urgc; - int noob = sosendoob(so); + noob = sosendoob(so); if (noob <= 0) goto err_disconnected; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libslirp-4.9.3+4/src/udp.c new/libslirp-4.9.5+1/src/udp.c --- old/libslirp-4.9.3+4/src/udp.c 2026-06-24 02:54:42.000000000 +0200 +++ new/libslirp-4.9.5+1/src/udp.c 2026-09-22 23:06:37.000000000 +0200 @@ -334,8 +334,9 @@ so->so_expire = curtime + SO_EXPIRE; slirp_insque(so, &so->slirp->udb); + slirp_set_nonblock(so->s); + slirp_register_poll_socket(so); } - slirp_register_poll_socket(so); return (so->s); } @@ -406,6 +407,7 @@ so->so_expire = 0; so->so_state &= SS_PERSISTENT_MASK; so->so_state |= SS_ISFCONNECTED | flags; + slirp_set_nonblock(so->s); slirp_register_poll_socket(so); return so; ++++++ libslirp.obsinfo ++++++ --- /var/tmp/diff_new_pack.LQE1va/_old 2026-09-29 17:47:43.570068326 +0200 +++ /var/tmp/diff_new_pack.LQE1va/_new 2026-09-29 17:47:43.573068451 +0200 @@ -1,5 +1,5 @@ name: libslirp -version: 4.9.3+4 -mtime: 1782262482 -commit: d82ac5a853813d70cb990bc31d6faeffe8e4dc51 +version: 4.9.5+1 +mtime: 1790111197 +commit: 62b298621dfc413a42d2181933f5335815afa1a4
