Vulnerabilidad · Publicado 22/09/2026
Se identificó un desbordamiento de búfer basado en heap en los constructores de respuesta DHCPv6 y TFTP de libslirp. Cuando el host está configurado con MTU pequeño, las opciones CLIENTID DHCPv6 o blksize TFTP suministradas por el guest pueden desbordar el búfer de respuesta con contenido controlado por atacante, resultando en negación de servicio y potencial ejecución remota de código en el proceso host. Esta vulnerabilidad afecta infraestructuras de virtualización en data centers y ambientes cloud en LATAM.
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
Score: 7.4/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-787
Publicado en NIST NVD.