CVE-2026-95508: Out-of-bounds Write in Red Hat Red Hat Enterprise Linux 10
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
AI Analysis
Technical Summary
This vulnerability involves a heap-based buffer overflow in libslirp's DHCPv6 and TFTP response builders. Specifically, when the host's interface MTU is set below the IPv6 minimum link MTU of 1280, an attacker-controlled DHCPv6 CLIENTID or TFTP blksize option from a guest can overflow the reply buffer. This overflow can cause denial of service or potentially allow arbitrary code execution within the host process. The default MTU configuration is not vulnerable. Red Hat's advisory recommends not configuring SlirpConfig.if_mtu below 1280 to mitigate the issue.
Potential Impact
Successful exploitation can result in denial of service by crashing the host process or potentially arbitrary code execution, compromising the integrity and availability of the affected system. There is no impact on confidentiality. The vulnerability requires network access but has high attack complexity and no privileges or user interaction required.
Mitigation Recommendations
Red Hat advises not to configure the SlirpConfig.if_mtu parameter below the IPv6 minimum link MTU of 1280. This configuration change mitigates the vulnerability without requiring a software patch. Check the Red Hat advisory for updates on official fixes or patches.
CVE-2026-95508: Out-of-bounds Write in Red Hat Red Hat Enterprise Linux 10
Description
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service and potentially arbitrary code execution in the host process. The default interface MTU is not affected.
CVSS v3.1
Score 7.4high
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat OpenShift Container Platform 4
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a heap-based buffer overflow in libslirp's DHCPv6 and TFTP response builders. Specifically, when the host's interface MTU is set below the IPv6 minimum link MTU of 1280, an attacker-controlled DHCPv6 CLIENTID or TFTP blksize option from a guest can overflow the reply buffer. This overflow can cause denial of service or potentially allow arbitrary code execution within the host process. The default MTU configuration is not vulnerable. Red Hat's advisory recommends not configuring SlirpConfig.if_mtu below 1280 to mitigate the issue.
Potential Impact
Successful exploitation can result in denial of service by crashing the host process or potentially arbitrary code execution, compromising the integrity and availability of the affected system. There is no impact on confidentiality. The vulnerability requires network access but has high attack complexity and no privileges or user interaction required.
Mitigation Recommendations
Red Hat advises not to configure the SlirpConfig.if_mtu parameter below the IPv6 minimum link MTU of 1280. This configuration change mitigates the vulnerability without requiring a software patch. Check the Red Hat advisory for updates on official fixes or patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-22T07:22:20.302Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-95508","vendor":"Red Hat"}]
Threat ID: 6ab240dbf7a7c54106ee6e2b
Added to database: 09/22/2026, 08:48:27 UTC
Last enriched: 09/22/2026, 09:02:49 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.