Page MenuHomeVyOS Platform

Accel-PPP: DHCPv6 Status Code option causes accel-pppd crash via OOB read in print_status()
Closed, ResolvedPublic

Description

A PPP subscriber with DHCPv6 enabled can crash accel-pppd by sending a crafted DHCPv6 Solicit containing an out-of-range Status Code option. In ipv6/dhcpv6_packet.c, print_status() uses sizeof(status_name) as a bounds check even though it is the byte size of the pointer array, not the element count. A missing comma between "UseMulticast" and "NoPrefixAvail" also shortens the array. As a result, attacker-controlled status codes can index past status_name[] during verbose logging and terminate the daemon. On our setup, Status Code = 12 reliably reproduced the crash.

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object in space S1 VyOS Public.
RC created this object with visibility "Administrators".
RC changed the edit policy from "Custom Policy" to "Maintainers (Project)".Apr 24 2026, 6:54 PM
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".Mon, Oct 5, 8:59 AM
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.