Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libslirp for openSUSE:Factory 
checked in at 2026-09-29 17:46:44
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libslirp (Old)
 and      /work/SRC/openSUSE:Factory/.libslirp.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libslirp"

Tue Sep 29 17:46:44 2026 rev:15 rq:1381144 version:4.9.5+1

Changes:
--------
--- /work/SRC/openSUSE:Factory/libslirp/libslirp.changes        2026-06-27 
18:03:50.243423169 +0200
+++ /work/SRC/openSUSE:Factory/.libslirp.new.383539/libslirp.changes    
2026-09-29 17:47:40.432937087 +0200
@@ -1,0 +2,17 @@
+Fri Sep 25 13:51:58 UTC 2026 - Petr Gajdos <[email protected]> + gemini
+
+- Update to version 4.9.5+1:
+  * note CVE numbers
+  * Release v4.9.5
+  * Set UDP sockets in blocking mode
+  * dhcpv6: fix bounding the reply against the interface MTU
+  * dhcpv6: bound the reply against the interface MTU
+  * ncsi: bounds-check OEM command bodies before dereferencing them
+  * Release v4.9.4
+  * ip_input: update hlen on ip_reass
+  * ip6_input: Trim mbuf to ip6-announced length
+  * Fix reporting oob output
+  * Note about the security contact
+- fixes CVE-2026-95507, CVE-2026-95508
+
+-------------------------------------------------------------------

Old:
----
  libslirp-4.9.3+4.obscpio

New:
----
  libslirp-4.9.5+1.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libslirp.spec ++++++
--- /var/tmp/diff_new_pack.LQE1va/_old  2026-09-29 17:47:42.994044229 +0200
+++ /var/tmp/diff_new_pack.LQE1va/_new  2026-09-29 17:47:42.996044312 +0200
@@ -19,7 +19,7 @@
 %define libname libslirp0
 
 Name:           libslirp
-Version:        4.9.3+4
+Version:        4.9.5+1
 Release:        0
 Summary:        A general purpose TCP-IP emulator
 License:        MIT

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.LQE1va/_old  2026-09-29 17:47:43.043046279 +0200
+++ /var/tmp/diff_new_pack.LQE1va/_new  2026-09-29 17:47:43.046046404 +0200
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param 
name="url">https://gitlab.freedesktop.org/slirp/libslirp.git</param>
-              <param 
name="changesrevision">d82ac5a853813d70cb990bc31d6faeffe8e4dc51</param></service></servicedata>
+              <param 
name="changesrevision">62b298621dfc413a42d2181933f5335815afa1a4</param></service></servicedata>
 (No newline at EOF)
 

++++++ libslirp-4.9.3+4.obscpio -> libslirp-4.9.5+1.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/CHANGELOG.md 
new/libslirp-4.9.5+1/CHANGELOG.md
--- old/libslirp-4.9.3+4/CHANGELOG.md   2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/CHANGELOG.md   2026-09-22 23:06:37.000000000 +0200
@@ -5,6 +5,32 @@
 The format is based on [Keep a 
Changelog](https://keepachangelog.com/en/1.0.0/),
 and this project adheres to [Semantic 
Versioning](https://semver.org/spec/v2.0.0.html).
 
+## [4.9.5] - 2026-09-22
+
+## Security
+
+  - Fix bounds-check in processing OEM commands (CVE-2026-95507)
+  - Fix bounds-check in dhcpv6 against MTU (CVE-2026-95508)
+
+### Fixed
+
+  - Fix blocking sendto on UDP ockets #97
+
+## [4.9.4] - 2026-08-25
+
+## Security
+
+  - Fix information leak on fragmented packets with different header lengths
+
+### Fixed
+
+  - Fix reporting oob output #95
+  - Fix buffer trimming to ip6-announced length #96
+
+## Changed
+
+  - slirp: permit guestfwd to vhost_addr/vnameserver_addr #81 #140
+
 ## [4.9.3] - 2026-05-26
 
 ### Fixed
@@ -289,7 +315,9 @@
  - Standalone project, removing any QEMU dependency.
  - License clarifications.
 
-[Unreleased]: 
https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.3...master
+[Unreleased]: 
https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.5...master
+[4.9.5]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.4...v4.9.5
+[4.9.4]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.3...v4.9.4
 [4.9.3]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.2...v4.9.3
 [4.9.2]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.1...v4.9.2
 [4.9.1]: https://gitlab.freedesktop.org/slirp/libslirp/compare/v4.9.0...v4.9.1
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/README.md 
new/libslirp-4.9.5+1/README.md
--- old/libslirp-4.9.3+4/README.md      2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/README.md      2026-09-22 23:06:37.000000000 +0200
@@ -45,6 +45,10 @@
 Alternatively, you may send patches to [email protected]
 mailing list.
 
+Security reports can be sent to [email protected]
+with pgp key 900CB024B67931D40F82304BD0178C767D069EE6 (it can be found
+in the debian keyring for instance)
+
 ## Debugging
 
 To make slirp emit debugging prints, one can use for instance:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/meson.build 
new/libslirp-4.9.5+1/meson.build
--- old/libslirp-4.9.3+4/meson.build    2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/meson.build    2026-09-22 23:06:37.000000000 +0200
@@ -1,5 +1,5 @@
 project('libslirp', 'c',
-  version : '4.9.3',
+  version : '4.9.5',
   license : 'BSD-3-Clause',
   default_options : ['warning_level=1', 'c_std=gnu99'],
   meson_version : '>= 0.60',
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/dhcpv6.c 
new/libslirp-4.9.5+1/src/dhcpv6.c
--- old/libslirp-4.9.3+4/src/dhcpv6.c   2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/src/dhcpv6.c   2026-09-22 23:06:37.000000000 +0200
@@ -157,6 +157,11 @@
     *resp++ = (uint8_t)xid;
 
     if (ri.client_id) {
+        if (resp + 4 + ri.client_id_len >
+            (uint8_t *)m->m_data + slirp->if_mtu) {
+            m_free(m); /* response would overflow the interface-MTU-sized mbuf 
*/
+            return;
+        }
         *resp++ = OPTION_CLIENTID >> 8; /* option-code high byte */
         *resp++ = OPTION_CLIENTID; /* option-code low byte */
         *resp++ = ri.client_id_len >> 8; /* option-len high byte */
@@ -165,6 +170,10 @@
         resp += ri.client_id_len;
     }
     if (ri.want_dns) {
+        if (resp + 4 + 16 > (uint8_t *)m->m_data + slirp->if_mtu) {
+            m_free(m); /* reply would not fit the interface-MTU-sized mbuf */
+            return;
+        }
         *resp++ = OPTION_DNS_SERVERS >> 8; /* option-code high byte */
         *resp++ = OPTION_DNS_SERVERS; /* option-code low byte */
         *resp++ = 0; /* option-len high byte */
@@ -176,9 +185,14 @@
         uint8_t *sa = slirp->vhost_addr6.s6_addr;
         int slen, smaxlen;
 
+        smaxlen = (uint8_t *)m->m_data + slirp->if_mtu - (resp + 4);
+        if (smaxlen < 0) {
+            m_free(m); /* boot-url would not fit the interface-MTU-sized mbuf 
*/
+            return;
+        }
+
         *resp++ = OPTION_BOOTFILE_URL >> 8; /* option-code high byte */
         *resp++ = OPTION_BOOTFILE_URL; /* option-code low byte */
-        smaxlen = (uint8_t *)m->m_data + slirp->if_mtu - (resp + 2);
         slen = slirp_fmt((char *)resp + 2, smaxlen,
                          "tftp://[%02x%02x:%02x%02x:%02x%02x:%02x%02x:";
                          "%02x%02x:%02x%02x:%02x%02x:%02x%02x]/%s",
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/ip6_input.c 
new/libslirp-4.9.5+1/src/ip6_input.c
--- old/libslirp-4.9.3+4/src/ip6_input.c        2026-06-24 02:54:42.000000000 
+0200
+++ new/libslirp-4.9.5+1/src/ip6_input.c        2026-09-22 23:06:37.000000000 
+0200
@@ -28,6 +28,7 @@
     M_DUP_DEBUG(slirp, m, 1, TCPIPHDR_DELTA + 2 + ETH_HLEN);
 
     struct ip6 *ip6;
+    int ip6_len;
 
     if (!slirp->in6_enabled) {
         goto bad;
@@ -47,7 +48,9 @@
         goto bad;
     }
 
-    if (ntohs(ip6->ip_pl) + sizeof(struct ip6) > slirp->if_mtu) {
+    ip6_len = ntohs(ip6->ip_pl) + sizeof(struct ip6);
+
+    if (ip6_len > slirp->if_mtu) {
         icmp6_send_error(m, ICMP6_TOOBIG, 0);
         goto bad;
     }
@@ -55,10 +58,14 @@
     // Check if the message size is big enough to hold what's
     // set in the payload length header. If not this is an invalid
     // packet
-    if (m->m_len < ntohs(ip6->ip_pl) + sizeof(struct ip6)) {
+    if (m->m_len < ip6_len) {
         goto bad;
     }
 
+    /* Should drop packet if mbuf too long? hmmm... */
+    if (m->m_len > ip6_len)
+        m_adj(m, ip6_len - m->m_len);
+
     /* check ip_ttl for a correct ICMP reply */
     if (ip6->ip_hl == 0) {
         icmp6_send_error(m, ICMP6_TIMXCEED, ICMP6_TIMXCEED_INTRANS);
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/ip_input.c 
new/libslirp-4.9.5+1/src/ip_input.c
--- old/libslirp-4.9.3+4/src/ip_input.c 2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/src/ip_input.c 2026-09-22 23:06:37.000000000 +0200
@@ -187,6 +187,7 @@
             if (ip == NULL)
                 return;
             m = dtom(slirp, ip);
+            hlen = ip->ip_hl << 2;
         } else if (q)
             ip_freef(slirp, q);
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/ncsi.c 
new/libslirp-4.9.5+1/src/ncsi.c
--- old/libslirp-4.9.3+4/src/ncsi.c     2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/src/ncsi.c     2026-09-22 23:06:37.000000000 +0200
@@ -58,7 +58,7 @@
 /* Response handler for Mellanox command Get Mac Address */
 static int ncsi_rsp_handler_oem_mlx_gma(Slirp *slirp,
                                         const struct ncsi_pkt_hdr *nh,
-                                        struct ncsi_rsp_pkt_hdr *rnh)
+                                        struct ncsi_rsp_pkt_hdr *rnh, int 
pkt_len)
 {
     uint8_t oob_eth_addr_allocated = 0;
     struct ncsi_rsp_oem_pkt *rsp;
@@ -85,7 +85,7 @@
 
 /* Response handler for Mellanox card */
 static int ncsi_rsp_handler_oem_mlx(Slirp *slirp, const struct ncsi_pkt_hdr 
*nh,
-                                    struct ncsi_rsp_pkt_hdr *rnh)
+                                    struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     const struct ncsi_cmd_oem_pkt *cmd;
     const struct ncsi_rsp_oem_mlx_pkt *cmd_mlx;
@@ -100,6 +100,14 @@
     rsp = (struct ncsi_rsp_oem_pkt *)rnh;
     rsp_mlx = (struct ncsi_rsp_oem_mlx_pkt *)rsp->data;
 
+    if (pkt_len < ETH_HLEN + sizeof(struct ncsi_cmd_oem_pkt) +
+                      sizeof(struct ncsi_rsp_oem_mlx_pkt)) {
+        rsp->rsp.common.length = htons(8);
+        rsp->rsp.code = htons(NCSI_PKT_RSP_C_UNSUPPORTED);
+        rsp->rsp.reason = htons(NCSI_PKT_RSP_R_UNKNOWN);
+        return -ENOENT;
+    }
+
     /* Ensure the OEM response header matches the command's */
     rsp_mlx->cmd_rev = cmd_mlx->cmd_rev;
     rsp_mlx->cmd = cmd_mlx->cmd;
@@ -108,7 +116,7 @@
 
     if (cmd_mlx->cmd == NCSI_OEM_MLX_CMD_GMA &&
         cmd_mlx->param == NCSI_OEM_MLX_CMD_GMA_PARAM)
-        return ncsi_rsp_handler_oem_mlx_gma(slirp, nh, rnh);
+        return ncsi_rsp_handler_oem_mlx_gma(slirp, nh, rnh, pkt_len);
 
     rsp->rsp.common.length = htons(8);
     rsp->rsp.code = htons(NCSI_PKT_RSP_C_UNSUPPORTED);
@@ -119,7 +127,7 @@
 static const struct ncsi_rsp_oem_handler {
     unsigned int mfr_id;
     int (*handler)(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                   struct ncsi_rsp_pkt_hdr *rnh);
+                   struct ncsi_rsp_pkt_hdr *rnh, int pkt_len);
 } ncsi_rsp_oem_handlers[] = {
     { NCSI_OEM_MFR_MLX_ID, ncsi_rsp_handler_oem_mlx },
     { NCSI_OEM_MFR_BCM_ID, NULL },
@@ -128,14 +136,18 @@
 
 /* Response handler for OEM command */
 static int ncsi_rsp_handler_oem(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                                struct ncsi_rsp_pkt_hdr *rnh)
+                                struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     const struct ncsi_rsp_oem_handler *nrh = NULL;
     const struct ncsi_cmd_oem_pkt *cmd = (const struct ncsi_cmd_oem_pkt *)nh;
     struct ncsi_rsp_oem_pkt *rsp = (struct ncsi_rsp_oem_pkt *)rnh;
-    uint32_t mfr_id = ntohl(cmd->mfr_id);
+    uint32_t mfr_id;
     int i;
 
+    if (pkt_len < ETH_HLEN + sizeof(struct ncsi_cmd_oem_pkt)) {
+        goto error;
+    }
+    mfr_id = ntohl(cmd->mfr_id);
     rsp->mfr_id = cmd->mfr_id;
 
     if (mfr_id != slirp->mfr_id) {
@@ -159,7 +171,7 @@
     }
 
     /* Process the packet */
-    return nrh->handler(slirp, nh, rnh);
+    return nrh->handler(slirp, nh, rnh, pkt_len);
 
 error:
     rsp->rsp.common.length = htons(8);
@@ -171,7 +183,7 @@
 
 /* Get Version ID */
 static int ncsi_rsp_handler_gvi(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                                struct ncsi_rsp_pkt_hdr *rnh)
+                                struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     struct ncsi_rsp_gvi_pkt *rsp = (struct ncsi_rsp_gvi_pkt *)rnh;
 
@@ -183,7 +195,7 @@
 
 /* Get Capabilities */
 static int ncsi_rsp_handler_gc(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                               struct ncsi_rsp_pkt_hdr *rnh)
+                               struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     struct ncsi_rsp_gc_pkt *rsp = (struct ncsi_rsp_gc_pkt *)rnh;
 
@@ -199,7 +211,7 @@
 
 /* Get Link status */
 static int ncsi_rsp_handler_gls(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                                struct ncsi_rsp_pkt_hdr *rnh)
+                                struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     struct ncsi_rsp_gls_pkt *rsp = (struct ncsi_rsp_gls_pkt *)rnh;
 
@@ -209,7 +221,7 @@
 
 /* Get Parameters */
 static int ncsi_rsp_handler_gp(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                               struct ncsi_rsp_pkt_hdr *rnh)
+                               struct ncsi_rsp_pkt_hdr *rnh, int pkt_len)
 {
     struct ncsi_rsp_gp_pkt *rsp = (struct ncsi_rsp_gp_pkt *)rnh;
 
@@ -226,7 +238,7 @@
     unsigned char type;
     int payload;
     int (*handler)(Slirp *slirp, const struct ncsi_pkt_hdr *nh,
-                   struct ncsi_rsp_pkt_hdr *rnh);
+                   struct ncsi_rsp_pkt_hdr *rnh, int pkt_len);
 } ncsi_rsp_handlers[] = { { NCSI_PKT_RSP_CIS, 4, NULL },     /* Clear Initial 
State */
                           { NCSI_PKT_RSP_SP, 4, NULL },      /* Select Package 
*/
                           { NCSI_PKT_RSP_DP, 4, NULL },      /* Deselect 
Package */
@@ -313,7 +325,7 @@
         rnh->reason = htons(NCSI_PKT_RSP_R_NO_ERROR);
 
         if (handler->handler) {
-            handler->handler(slirp, nh, rnh);
+            handler->handler(slirp, nh, rnh, pkt_len);
         }
         ncsi_rsp_len += ntohs(rnh->common.length);
     } else {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/socket.c 
new/libslirp-4.9.5+1/src/socket.c
--- old/libslirp-4.9.3+4/src/socket.c   2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/src/socket.c   2026-09-22 23:06:37.000000000 +0200
@@ -418,7 +418,7 @@
 
     if (so->so_urgc) {
         uint32_t expected = so->so_urgc;
-        int noob = sosendoob(so);
+        noob = sosendoob(so);
 
         if (noob <= 0)
             goto err_disconnected;
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/libslirp-4.9.3+4/src/udp.c 
new/libslirp-4.9.5+1/src/udp.c
--- old/libslirp-4.9.3+4/src/udp.c      2026-06-24 02:54:42.000000000 +0200
+++ new/libslirp-4.9.5+1/src/udp.c      2026-09-22 23:06:37.000000000 +0200
@@ -334,8 +334,9 @@
 
         so->so_expire = curtime + SO_EXPIRE;
         slirp_insque(so, &so->slirp->udb);
+        slirp_set_nonblock(so->s);
+        slirp_register_poll_socket(so);
     }
-    slirp_register_poll_socket(so);
     return (so->s);
 }
 
@@ -406,6 +407,7 @@
         so->so_expire = 0;
     so->so_state &= SS_PERSISTENT_MASK;
     so->so_state |= SS_ISFCONNECTED | flags;
+    slirp_set_nonblock(so->s);
     slirp_register_poll_socket(so);
 
     return so;

++++++ libslirp.obsinfo ++++++
--- /var/tmp/diff_new_pack.LQE1va/_old  2026-09-29 17:47:43.570068326 +0200
+++ /var/tmp/diff_new_pack.LQE1va/_new  2026-09-29 17:47:43.573068451 +0200
@@ -1,5 +1,5 @@
 name: libslirp
-version: 4.9.3+4
-mtime: 1782262482
-commit: d82ac5a853813d70cb990bc31d6faeffe8e4dc51
+version: 4.9.5+1
+mtime: 1790111197
+commit: 62b298621dfc413a42d2181933f5335815afa1a4
 

Reply via email to