Re: [PATCH for-5.0?] slirp: update to fix CVE-2020-1983

2020-04-22 Thread Peter Maydell
On Tue, 21 Apr 2020 at 20:19, Peter Maydell wrote: > > On Tue, 21 Apr 2020 at 18:03, Marc-André Lureau > wrote: > > > > This is an update on the stable-4.2 branch of libslirp.git: > > > > git shortlog 55ab21c9a3..2faae0f778f81 > > > > Marc-André Lureau (1): > > Fix use-afte-free in

Re: [PATCH for-5.0?] slirp: update to fix CVE-2020-1983

2020-04-21 Thread Peter Maydell
On Tue, 21 Apr 2020 at 18:03, Marc-André Lureau wrote: > > This is an update on the stable-4.2 branch of libslirp.git: > > git shortlog 55ab21c9a3..2faae0f778f81 > > Marc-André Lureau (1): > Fix use-afte-free in ip_reass() (CVE-2020-1983) > > CVE-2020-1983 is actually a follow up fix for

[PATCH for-5.0?] slirp: update to fix CVE-2020-1983

2020-04-21 Thread Marc-André Lureau
This is an update on the stable-4.2 branch of libslirp.git: git shortlog 55ab21c9a3..2faae0f778f81 Marc-André Lureau (1): Fix use-afte-free in ip_reass() (CVE-2020-1983) CVE-2020-1983 is actually a follow up fix for commit 126c04acbabd7ad32c2b018fe10dfac2a3bc1210 ("Fix heap overflow in