From: Marc-André Lureau Date: Tue, 21 Apr 2020 17:02:27 +0000 (+0200) Subject: slirp: update to fix CVE-2020-1983 X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=7769c23774d1278f60b9e40d2c0b98784de6425f;p=qemu.git slirp: update to fix CVE-2020-1983 This is an update on the stable-4.2 branch of libslirp.git: git shortlog 55ab21c9a3..2faae0f778f81 Marc-André Lureau (1): Fix use-afte-free in ip_reass() (CVE-2020-1983) CVE-2020-1983 is actually a follow up fix for commit 126c04acbabd7ad32c2b018fe10dfac2a3bc1210 ("Fix heap overflow in ip_reass on big packet input") which was was included in qemu v4.1 (commit e1a4a24d262ba5ac74ea1795adb3ab1cd574c7fb "slirp: update with CVE-2019-14378 fix"). Signed-off-by: Marc-André Lureau Message-id: 20200421170227.843555-1-marcandre.lureau@redhat.com Signed-off-by: Peter Maydell --- diff --git a/slirp b/slirp index 55ab21c9a3..2faae0f778 160000 --- a/slirp +++ b/slirp @@ -1 +1 @@ -Subproject commit 55ab21c9a36852915b81f1b41ebaf3b6509dd8ba +Subproject commit 2faae0f778f818fadc873308f983289df697eb93