Status: UPDATED
| Advisory ID: CVE-2026-95508
Key Details
| CVE | CVE-2026-95508 |
| CVSS Score / Version | 7.4 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat Enterprise Linux 10, Red Hat Red Hat Enterprise Linux 8, Red Hat Red Hat Enterprise Linux 9, and Red Hat Red Hat OpenShift Container Platform 4 |
| Classified as | CWE-787 (Out-of-bounds Write) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References