]> git.ipfire.org Git - thirdparty/bird.git/commit
OSPF: Fix OOB read in Router-LSA validation master
authorOndrej Zajicek <santiago@crfreenet.org>
Sat, 6 Jun 2026 16:04:03 +0000 (18:04 +0200)
committerOndrej Zajicek <santiago@crfreenet.org>
Sat, 6 Jun 2026 16:13:40 +0000 (18:13 +0200)
commit7023632d3b4fb578c3d511b42d69edec6ab6c18d
tree33f1c5e8d3bc0091abb1c55356d4e5acd7792634
parent2f563413ebb17f6282f0f0bb91975e323e0fc451
OSPF: Fix OOB read in Router-LSA validation

The missing check in lsa_validate_rt2() may lead to OOB read in OSPFv2
Router-LSA validation for malformed Router-LSAs. The OSPFv3 case is in
fact safe, but the patch improves these checks in uniform way.

Reported-By: TristanInSec@gmail.com
proto/ospf/lsalib.c