{"id":"UBUNTU-CVE-2019-14378","details":"ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.","modified":"2026-05-20T16:06:15.308877466Z","published":"2019-07-29T11:15:00Z","related":["USN-4191-1","USN-4191-2"],"upstream":["CVE-2019-14378"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2019-14378"},{"type":"REPORT","url":"https://gitlab.freedesktop.org/slirp/libslirp/commit/126c04acbabd7ad32c2b018fe10dfac2a3bc1210"},{"type":"REPORT","url":"https://vishnudevtj.github.io/notes/qemu-vm-escape-cve-2019-14378"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4191-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4191-2"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2019-14378"}],"affected":[{"package":{"name":"qemu","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/qemu?arch=source&distro=trusty%2Fesm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.0+dfsg-2ubuntu1.47"}]}],"versions":["1.5.0+dfsg-3ubuntu5","1.5.0+dfsg-3ubuntu6","1.6.0+dfsg-2ubuntu1","1.6.0+dfsg-2ubuntu2","1.6.0+dfsg-2ubuntu3","1.6.0+dfsg-2ubuntu4","1.7.0+dfsg-2ubuntu1","1.7.0+dfsg-2ubuntu2","1.7.0+dfsg-2ubuntu3","1.7.0+dfsg-2ubuntu4","1.7.0+dfsg-2ubuntu5","1.7.0+dfsg-2ubuntu7","1.7.0+dfsg-2ubuntu8","1.7.0+dfsg-2ubuntu9","1.7.0+dfsg-3ubuntu1~ppa1","1.7.0+dfsg-3ubuntu1","1.7.0+dfsg-3ubuntu2","1.7.0+dfsg-3ubuntu3","1.7.0+dfsg-3ubuntu4","1.7.0+dfsg-3ubuntu5","1.7.0+dfsg-3ubuntu6","1.7.0+dfsg-3ubuntu7","2.0.0~rc1+dfsg-0ubuntu1","2.0.0~rc1+dfsg-0ubuntu2","2.0.0~rc1+dfsg-0ubuntu3","2.0.0~rc1+dfsg-0ubuntu3.1","2.0.0+dfsg-2ubuntu1","2.0.0+dfsg-2ubuntu1.1","2.0.0+dfsg-2ubuntu1.2","2.0.0+dfsg-2ubuntu1.3","2.0.0+dfsg-2ubuntu1.5","2.0.0+dfsg-2ubuntu1.6","2.0.0+dfsg-2ubuntu1.7","2.0.0+dfsg-2ubuntu1.8","2.0.0+dfsg-2ubuntu1.9","2.0.0+dfsg-2ubuntu1.10","2.0.0+dfsg-2ubuntu1.11","2.0.0+dfsg-2ubuntu1.13","2.0.0+dfsg-2ubuntu1.14","2.0.0+dfsg-2ubuntu1.15","2.0.0+dfsg-2ubuntu1.16","2.0.0+dfsg-2ubuntu1.17","2.0.0+dfsg-2ubuntu1.18","2.0.0+dfsg-2ubuntu1.19","2.0.0+dfsg-2ubuntu1.20","2.0.0+dfsg-2ubuntu1.21","2.0.0+dfsg-2ubuntu1.22","2.0.0+dfsg-2ubuntu1.24","2.0.0+dfsg-2ubuntu1.25","2.0.0+dfsg-2ubuntu1.26","2.0.0+dfsg-2ubuntu1.27","2.0.0+dfsg-2ubuntu1.28","2.0.0+dfsg-2ubuntu1.29","2.0.0+dfsg-2ubuntu1.30","2.0.0+dfsg-2ubuntu1.31","2.0.0+dfsg-2ubuntu1.32","2.0.0+dfsg-2ubuntu1.33","2.0.0+dfsg-2ubuntu1.34","2.0.0+dfsg-2ubuntu1.35","2.0.0+dfsg-2ubuntu1.36","2.0.0+dfsg-2ubuntu1.38","2.0.0+dfsg-2ubuntu1.39","2.0.0+dfsg-2ubuntu1.40","2.0.0+dfsg-2ubuntu1.41","2.0.0+dfsg-2ubuntu1.42","2.0.0+dfsg-2ubuntu1.43","2.0.0+dfsg-2ubuntu1.44","2.0.0+dfsg-2ubuntu1.45","2.0.0+dfsg-2ubuntu1.46"],"ecosystem_specific":{"binaries":[{"binary_name":"qemu","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_name":"qemu-common","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-guest-agent"},{"binary_name":"qemu-keymaps","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_name":"qemu-kvm","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_name":"qemu-system","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-system-aarch64"},{"binary_name":"qemu-system-arm","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-system-common"},{"binary_name":"qemu-system-mips","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_name":"qemu-system-misc","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-system-ppc"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-system-sparc"},{"binary_name":"qemu-system-x86","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-user"},{"binary_name":"qemu-user-static","binary_version":"2.0.0+dfsg-2ubuntu1.47"},{"binary_version":"2.0.0+dfsg-2ubuntu1.47","binary_name":"qemu-utils"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-7","1:1.0.17-7+deb8u2build0.14.04.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.0.17-7+deb8u2build0.14.04.1+esm1","binary_name":"slirp"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"qemu","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/qemu?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.5+dfsg-5ubuntu10.42"}]}],"versions":["1:2.3+dfsg-5ubuntu9","1:2.3+dfsg-5ubuntu10","1:2.4+dfsg-4ubuntu1","1:2.4+dfsg-4ubuntu2","1:2.4+dfsg-4ubuntu3","1:2.4+dfsg-5ubuntu3","1:2.5+dfsg-1ubuntu2","1:2.5+dfsg-1ubuntu3","1:2.5+dfsg-1ubuntu4","1:2.5+dfsg-1ubuntu5","1:2.5+dfsg-5ubuntu1","1:2.5+dfsg-5ubuntu2","1:2.5+dfsg-5ubuntu4","1:2.5+dfsg-5ubuntu6","1:2.5+dfsg-5ubuntu7","1:2.5+dfsg-5ubuntu10","1:2.5+dfsg-5ubuntu10.1","1:2.5+dfsg-5ubuntu10.2","1:2.5+dfsg-5ubuntu10.3","1:2.5+dfsg-5ubuntu10.4","1:2.5+dfsg-5ubuntu10.5","1:2.5+dfsg-5ubuntu10.6","1:2.5+dfsg-5ubuntu10.7","1:2.5+dfsg-5ubuntu10.8","1:2.5+dfsg-5ubuntu10.9","1:2.5+dfsg-5ubuntu10.10","1:2.5+dfsg-5ubuntu10.11","1:2.5+dfsg-5ubuntu10.13","1:2.5+dfsg-5ubuntu10.14","1:2.5+dfsg-5ubuntu10.15","1:2.5+dfsg-5ubuntu10.16","1:2.5+dfsg-5ubuntu10.20","1:2.5+dfsg-5ubuntu10.21","1:2.5+dfsg-5ubuntu10.22","1:2.5+dfsg-5ubuntu10.24","1:2.5+dfsg-5ubuntu10.25","1:2.5+dfsg-5ubuntu10.26","1:2.5+dfsg-5ubuntu10.28","1:2.5+dfsg-5ubuntu10.29","1:2.5+dfsg-5ubuntu10.30","1:2.5+dfsg-5ubuntu10.31","1:2.5+dfsg-5ubuntu10.32","1:2.5+dfsg-5ubuntu10.33","1:2.5+dfsg-5ubuntu10.34","1:2.5+dfsg-5ubuntu10.35","1:2.5+dfsg-5ubuntu10.36","1:2.5+dfsg-5ubuntu10.37","1:2.5+dfsg-5ubuntu10.38","1:2.5+dfsg-5ubuntu10.39","1:2.5+dfsg-5ubuntu10.40","1:2.5+dfsg-5ubuntu10.41"],"ecosystem_specific":{"binaries":[{"binary_name":"qemu","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-block-extra","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-guest-agent"},{"binary_name":"qemu-kvm","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-system"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-system-aarch64"},{"binary_name":"qemu-system-arm","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-system-common","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-system-mips","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-system-misc","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-system-ppc"},{"binary_name":"qemu-system-s390x","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-system-sparc","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-system-x86"},{"binary_name":"qemu-user","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-user-binfmt","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_name":"qemu-user-static","binary_version":"1:2.5+dfsg-5ubuntu10.42"},{"binary_version":"1:2.5+dfsg-5ubuntu10.42","binary_name":"qemu-utils"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"android","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/android?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["20150818-1500-0ubuntu2","20150818-1500-0ubuntu3","20160307-0742-0ubuntu3","20160330-0939-0ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"android","binary_version":"20160330-0939-0ubuntu1"},{"binary_version":"20160330-0939-0ubuntu1","binary_name":"android-copyright"},{"binary_version":"20160330-0939-0ubuntu1","binary_name":"android-emulator"},{"binary_version":"20160330-0939-0ubuntu1","binary_name":"ubuntu-emulator-images"},{"binary_name":"ubuntu-emulator-runtime","binary_version":"20160330-0939-0ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20120331-4"],"ecosystem_specific":{"binaries":[{"binary_name":"basilisk2","binary_version":"0.9.20120331-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6-2build1","2.6-5","2.6-5build1"],"ecosystem_specific":{"binaries":[{"binary_name":"bochs","binary_version":"2.6-5build1"},{"binary_version":"2.6-5build1","binary_name":"bochs-sdl"},{"binary_name":"bochs-term","binary_version":"2.6-5build1"},{"binary_name":"bochs-wx","binary_version":"2.6-5build1"},{"binary_version":"2.6-5build1","binary_name":"bochs-x"},{"binary_version":"2.6-5build1","binary_name":"bochsbios"},{"binary_name":"bximage","binary_version":"2.6-5build1"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.6-5build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.4.1+ds-3ubuntu1","2.6.1+dfsg-2","2.6.2+dfsg-2","2.6.2+dfsg-3","2.6.2+dfsg-3build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6.2+dfsg-3build1","binary_name":"fs-uae"},{"binary_version":"2.6.2+dfsg-3build1","binary_name":"fs-uae-arcade"},{"binary_name":"fs-uae-launcher","binary_version":"2.6.2+dfsg-3build1"},{"binary_name":"fs-uae-netplay-server","binary_version":"2.6.2+dfsg-3build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-8","1:1.0.17-8ubuntu16.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"slirp","binary_version":"1:1.0.17-8ubuntu16.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-2"},{"binary_name":"libvdeplug2","binary_version":"2.3.2+r586-2"},{"binary_name":"vde2","binary_version":"2.3.2+r586-2"},{"binary_name":"vde2-cryptcab","binary_version":"2.3.2+r586-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"qemu","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/qemu?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.11+dfsg-1ubuntu7.20"}]}],"versions":["1:2.10+dfsg-0ubuntu3","1:2.10+dfsg-0ubuntu4","1:2.10+dfsg-0ubuntu5","1:2.11+dfsg-1ubuntu1","1:2.11+dfsg-1ubuntu2","1:2.11+dfsg-1ubuntu4","1:2.11+dfsg-1ubuntu5","1:2.11+dfsg-1ubuntu6","1:2.11+dfsg-1ubuntu7","1:2.11+dfsg-1ubuntu7.1","1:2.11+dfsg-1ubuntu7.2","1:2.11+dfsg-1ubuntu7.3","1:2.11+dfsg-1ubuntu7.4","1:2.11+dfsg-1ubuntu7.5","1:2.11+dfsg-1ubuntu7.6","1:2.11+dfsg-1ubuntu7.7","1:2.11+dfsg-1ubuntu7.8","1:2.11+dfsg-1ubuntu7.9","1:2.11+dfsg-1ubuntu7.10","1:2.11+dfsg-1ubuntu7.12","1:2.11+dfsg-1ubuntu7.13","1:2.11+dfsg-1ubuntu7.14","1:2.11+dfsg-1ubuntu7.15","1:2.11+dfsg-1ubuntu7.17","1:2.11+dfsg-1ubuntu7.18","1:2.11+dfsg-1ubuntu7.19"],"ecosystem_specific":{"binaries":[{"binary_name":"qemu","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-block-extra"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-guest-agent"},{"binary_name":"qemu-kvm","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-system","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-system-arm","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-system-common","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-system-mips"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-system-misc"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-system-ppc"},{"binary_name":"qemu-system-s390x","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-system-sparc"},{"binary_name":"qemu-system-x86","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-user","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-user-binfmt","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_name":"qemu-user-static","binary_version":"1:2.11+dfsg-1ubuntu7.20"},{"binary_version":"1:2.11+dfsg-1ubuntu7.20","binary_name":"qemu-utils"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20120331-4","0.9.20120331-4.2"],"ecosystem_specific":{"binaries":[{"binary_name":"basilisk2","binary_version":"0.9.20120331-4.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6-5build1","2.6-5build2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6-5build2","binary_name":"bochs"},{"binary_name":"bochs-sdl","binary_version":"2.6-5build2"},{"binary_name":"bochs-term","binary_version":"2.6-5build2"},{"binary_version":"2.6-5build2","binary_name":"bochs-wx"},{"binary_name":"bochs-x","binary_version":"2.6-5build2"},{"binary_version":"2.6-5build2","binary_name":"bochsbios"},{"binary_name":"bximage","binary_version":"2.6-5build2"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.6-5build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.3+dfsg-1","2.8.4+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"fs-uae","binary_version":"2.8.4+dfsg-1"},{"binary_name":"fs-uae-arcade","binary_version":"2.8.4+dfsg-1"},{"binary_name":"fs-uae-launcher","binary_version":"2.8.4+dfsg-1"},{"binary_name":"fs-uae-netplay-server","binary_version":"2.8.4+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-8","1:1.0.17-8build1","1:1.0.17-8ubuntu18.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"slirp","binary_version":"1:1.0.17-8ubuntu18.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-2.1","2.3.2+r586-2.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-2.1build1"},{"binary_name":"libvdeplug2","binary_version":"2.3.2+r586-2.1build1"},{"binary_version":"2.3.2+r586-2.1build1","binary_name":"vde2"},{"binary_version":"2.3.2+r586-2.1build1","binary_name":"vde2-cryptcab"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"qemu","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/qemu?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:4.2-1ubuntu1"}]}],"versions":["1:4.0+dfsg-0ubuntu9","1:4.0+dfsg-0ubuntu10"],"ecosystem_specific":{"binaries":[{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-block-extra"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-guest-agent"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-kvm"},{"binary_name":"qemu-system","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-system-arm","binary_version":"1:4.2-1ubuntu1"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-system-common"},{"binary_name":"qemu-system-data","binary_version":"1:4.2-1ubuntu1"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-system-gui"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-system-mips"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-system-misc"},{"binary_name":"qemu-system-ppc","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-system-s390x","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-system-sparc","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-system-x86","binary_version":"1:4.2-1ubuntu1"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-system-x86-xen"},{"binary_version":"1:4.2-1ubuntu1","binary_name":"qemu-user"},{"binary_name":"qemu-user-binfmt","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-user-static","binary_version":"1:4.2-1ubuntu1"},{"binary_name":"qemu-utils","binary_version":"1:4.2-1ubuntu1"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20180101-1build2","0.9.20180101-1build3"],"ecosystem_specific":{"binaries":[{"binary_version":"0.9.20180101-1build3","binary_name":"basilisk2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.9+dfsg-3build1","2.6.9+dfsg-4","2.6.9+dfsg-5","2.6.10+dfsg-2","2.6.11+dfsg-1","2.6.11+dfsg-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6.11+dfsg-1build1","binary_name":"bochs"},{"binary_version":"2.6.11+dfsg-1build1","binary_name":"bochs-sdl"},{"binary_version":"2.6.11+dfsg-1build1","binary_name":"bochs-term"},{"binary_version":"2.6.11+dfsg-1build1","binary_name":"bochs-wx"},{"binary_name":"bochs-x","binary_version":"2.6.11+dfsg-1build1"},{"binary_name":"bochsbios","binary_version":"2.6.11+dfsg-1build1"},{"binary_name":"bximage","binary_version":"2.6.11+dfsg-1build1"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.6.11+dfsg-1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.4+dfsg-2build1","3.0.2+dfsg-1","3.0.2+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_version":"3.0.2+dfsg-2","binary_name":"fs-uae"},{"binary_name":"fs-uae-arcade","binary_version":"3.0.2+dfsg-2"},{"binary_name":"fs-uae-launcher","binary_version":"3.0.2+dfsg-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-8build2","1:1.0.17-9","1:1.0.17-10"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.0.17-10","binary_name":"slirp"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-2.2build1"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-2.2build1"},{"binary_version":"2.3.2+r586-2.2build1","binary_name":"libvdeplug2"},{"binary_name":"vde2","binary_version":"2.3.2+r586-2.2build1"},{"binary_version":"2.3.2+r586-2.2build1","binary_name":"vde2-cryptcab"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20180101-1build5","0.9.20180101-1build6"],"ecosystem_specific":{"binaries":[{"binary_name":"basilisk2","binary_version":"0.9.20180101-1build6"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.11+dfsg-4","2.7+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"bochs","binary_version":"2.7+dfsg-2"},{"binary_version":"2.7+dfsg-2","binary_name":"bochs-sdl"},{"binary_name":"bochs-term","binary_version":"2.7+dfsg-2"},{"binary_name":"bochs-wx","binary_version":"2.7+dfsg-2"},{"binary_name":"bochs-x","binary_version":"2.7+dfsg-2"},{"binary_version":"2.7+dfsg-2","binary_name":"bochsbios"},{"binary_version":"2.7+dfsg-2","binary_name":"bximage"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.7+dfsg-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.0.5+dfsg-1","3.1.35-1","3.1.47-1","3.1.59-1","3.1.62-1","3.1.66-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.1.66-1","binary_name":"fs-uae"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-11"],"ecosystem_specific":{"binaries":[{"binary_name":"slirp","binary_version":"1:1.0.17-11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-7","2.3.2+r586-8"],"ecosystem_specific":{"binaries":[{"binary_version":"2.3.2+r586-8","binary_name":"libvde0"},{"binary_version":"2.3.2+r586-8","binary_name":"vde-switch"},{"binary_name":"vde-wirefilter","binary_version":"2.3.2+r586-8"},{"binary_version":"2.3.2+r586-8","binary_name":"vde2"},{"binary_name":"vde2-cryptcab","binary_version":"2.3.2+r586-8"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20230516-2","0.9.20230516-2ubuntu1","0.9.20230516-2ubuntu2","0.9.20240401-1"],"ecosystem_specific":{"binaries":[{"binary_name":"basilisk2","binary_version":"0.9.20240401-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7+dfsg-4build1","2.7+dfsg-4build4","2.7+dfsg-4build5"],"ecosystem_specific":{"binaries":[{"binary_name":"bochs","binary_version":"2.7+dfsg-4build5"},{"binary_name":"bochs-sdl","binary_version":"2.7+dfsg-4build5"},{"binary_version":"2.7+dfsg-4build5","binary_name":"bochs-term"},{"binary_name":"bochs-wx","binary_version":"2.7+dfsg-4build5"},{"binary_name":"bochs-x","binary_version":"2.7+dfsg-4build5"},{"binary_name":"bochsbios","binary_version":"2.7+dfsg-4build5"},{"binary_version":"2.7+dfsg-4build5","binary_name":"bximage"},{"binary_version":"2.7+dfsg-4build5","binary_name":"sb16ctrl-bochs"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.66-2","3.1.66-2build1","3.1.66-2build2"],"ecosystem_specific":{"binaries":[{"binary_version":"3.1.66-2build2","binary_name":"fs-uae"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-11"],"ecosystem_specific":{"binaries":[{"binary_name":"slirp","binary_version":"1:1.0.17-11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-8","2.3.2+r586-9","2.3.2+r586-9.1ubuntu3","2.3.2+r586-9.1ubuntu4","2.3.2+r586-10"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-10"},{"binary_name":"vde-switch","binary_version":"2.3.2+r586-10"},{"binary_name":"vde-wirefilter","binary_version":"2.3.2+r586-10"},{"binary_name":"vde2","binary_version":"2.3.2+r586-10"},{"binary_version":"2.3.2+r586-10","binary_name":"vde2-cryptcab"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20240402+dfsg-1","0.9.20240402+dfsg-1build1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.9.20240402+dfsg-1build1","binary_name":"basilisk2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_name":"bochs","binary_version":"2.8+dfsg-1"},{"binary_name":"bochs-sdl","binary_version":"2.8+dfsg-1"},{"binary_name":"bochs-term","binary_version":"2.8+dfsg-1"},{"binary_version":"2.8+dfsg-1","binary_name":"bochs-wx"},{"binary_version":"2.8+dfsg-1","binary_name":"bochs-x"},{"binary_name":"bochsbios","binary_version":"2.8+dfsg-1"},{"binary_name":"bximage","binary_version":"2.8+dfsg-1"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.8+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.66-2build2"],"ecosystem_specific":{"binaries":[{"binary_name":"fs-uae","binary_version":"3.1.66-2build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-11"],"ecosystem_specific":{"binaries":[{"binary_version":"1:1.0.17-11","binary_name":"slirp"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-11"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-11"},{"binary_name":"vde-switch","binary_version":"2.3.2+r586-11"},{"binary_version":"2.3.2+r586-11","binary_name":"vde-wirefilter"},{"binary_name":"vde2","binary_version":"2.3.2+r586-11"},{"binary_version":"2.3.2+r586-11","binary_name":"vde2-cryptcab"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"basilisk2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/basilisk2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.9.20240402+dfsg-1build1","0.9.20251105+dfsg-1","0.9.20251105+dfsg-1.1","0.9.20251105+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.9.20251105+dfsg-2","binary_name":"basilisk2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"bochs","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/bochs?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.8+dfsg-1","binary_name":"bochs"},{"binary_version":"2.8+dfsg-1","binary_name":"bochs-sdl"},{"binary_version":"2.8+dfsg-1","binary_name":"bochs-term"},{"binary_name":"bochs-wx","binary_version":"2.8+dfsg-1"},{"binary_name":"bochs-x","binary_version":"2.8+dfsg-1"},{"binary_name":"bochsbios","binary_version":"2.8+dfsg-1"},{"binary_version":"2.8+dfsg-1","binary_name":"bximage"},{"binary_name":"sb16ctrl-bochs","binary_version":"2.8+dfsg-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"fs-uae","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/fs-uae?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.66-2build2","3.2.35-2"],"ecosystem_specific":{"binaries":[{"binary_name":"fs-uae","binary_version":"3.2.35-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"slirp","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/slirp?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:1.0.17-11","1:1.0.17-12"],"ecosystem_specific":{"binaries":[{"binary_name":"slirp","binary_version":"1:1.0.17-12"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}},{"package":{"name":"vde2","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/vde2?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.2+r586-11","2.3.2+r586-12","2.3.2+r586-12.1","2.3.2+r586-12.2"],"ecosystem_specific":{"binaries":[{"binary_name":"libvde0","binary_version":"2.3.2+r586-12.2"},{"binary_version":"2.3.2+r586-12.2","binary_name":"vde-switch"},{"binary_name":"vde-wirefilter","binary_version":"2.3.2+r586-12.2"},{"binary_name":"vde2","binary_version":"2.3.2+r586-12.2"},{"binary_name":"vde2-cryptcab","binary_version":"2.3.2+r586-12.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-14378.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"low"}]}