Page MenuHomeVyOS Platform

Accel-PPP remote DoS - Case: Bad AFTR-Name option in DHCPv6 SOLICIT
Closed, ResolvedPublic

Description

IPoE/PPPoE subscriber with active session can crash accel-ppp process by sending crafted IPv6 UDP DHCPv6 Solicit with a bad AFTR-Name (opt 64)

Vyos Config:

set interfaces ethernet eth1 address '192.0.2.1/24'
set service ipoe-server authentication mode 'noauth'
set service ipoe-server client-ip-pool default range '192.0.2.10-192.0.2.200'
set service ipoe-server client-ipv6-pool POOL prefix 2001:db8:1::/64 mask '64'
set service ipoe-server default-ipv6-pool 'POOL'
set service ipoe-server default-pool 'default'
set service ipoe-server gateway-address '192.0.2.1/32'
set service ipoe-server interface eth1 client-subnet '192.0.2.0/24'
set service ipoe-server interface eth1 mode 'l2'
set service ipoe-server interface eth1 network 'shared'

Attacker:
set interfaces ethernet eth0 address 'dhcp'

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object in space S1 VyOS Public.
RC created this object with visibility "Administrators".
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".Mon, Oct 5, 9:00 AM
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.