A PPP subscriber with DHCPv6 enabled can crash accel-pppd by sending a crafted DHCPv6 Solicit containing an out-of-range Status Code option. In ipv6/dhcpv6_packet.c, print_status() uses sizeof(status_name) as a bounds check even though it is the byte size of the pointer array, not the element count. A missing comma between "UseMulticast" and "NoPrefixAvail" also shortens the array. As a result, attacker-controlled status codes can index past status_name[] during verbose logging and terminate the daemon. On our setup, Status Code = 12 reliably reproduced the crash.
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Security vulnerability