Page MenuHomeVyOS Platform

Accel-PPP: stack buffer overflow via oversized RADIUS Accel-VRF-Name
Closed, ResolvedPublic

Description

Inbound RADIUS Vendor specific attribute parsing accepts a long string for Accel-VRF-Name.
That value is stored as session vrf_name without checking Linux interface-name constraints.

During session activation, vrf_name is copied into ifreq.ifr_name (fixed 16 bytes including NUL) with unbounded strcpy.
A long value (for example 253-byte RADIUS string) overwrites stack state, so later pointer use crashes with non-canonical address dereference.

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object in space S1 VyOS Public.
RC created this object with visibility "Administrators".
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".Mon, Oct 5, 8:58 AM
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.