Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freedesktop.org
Freedesktop.org libslirp |
|
| Vendors & Products |
Freedesktop.org
Freedesktop.org libslirp |
Wed, 24 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Jun 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker (root or CAP_NET_RAW) to leak gigabytes of sensitive host-process heap memory via sending crafted TCP segments with manipulated URG flags and urgent pointers (ti_urp). | |
| Title | libslirp TCP URG OOB Read Information Leak | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2026-06-24T12:39:59.831Z
Reserved: 2026-05-26T02:36:53.227Z
Link: CVE-2026-9539
Updated: 2026-06-24T12:39:56.720Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T16:05:09Z