Page MenuHomeVyOS Platform

openNHRP: state poisoning via Error Indication auth bypass
Closed, ResolvedPublic

Description

The auth check at nhrp_packet.c:817-819 skips authentication for Error Indication packets with error.code = AUTHENTICATION_FAILURE. An unauthenticated attacker can forge Error Indications that:

  1. Bypass auth completely (no token needed)
  2. Cancel pending NHRP requests (matching by predictable request_id)
  3. Inject NEGATIVE cache entries (block legitimate resolution for 3 min)
  4. Prevent spoke registration with the hub

Auth bypass condition (line 817-819): if (auth_token && (type != ERROR_INDICATION || code != AUTH_FAILURE)) → ERROR_INDICATION + AUTH_FAILURE → condition is FALSE → auth SKIPPED

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object with visibility "Administrators".
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.