oss-sec mailing list archives

Re: BIRD/BIRD2: stack buffer overflow in BGP AS_PATH mask matching, CVE pending


From: Stuart Henderson <stu () spacehopper org>
Date: Tue, 2 Jun 2026 11:56:57 +0100

On 2026/06/02 10:07, Bakabaka_9 wrote:
Tested affected:

- BIRD 2.16.2

Possibly affected:

- Other BIRD 2.x versions using the same AS_PATH mask matching
  implementation.

Not affected:

- Unknown.

Fixed version
=============

No fixed version is available at the time of this disclosure.

If you've only tried one version from April 2025, how can you can say
with certainty that it's not been fixed since then?


Current thread: