Fix CVE-2026-37460: EVPN and ENCAP/VNC packet parsing validation
Backport upstream commit 7676cad65114 to fix CVE-2026-37460.
The patch adds input validation for EVPN Type-2/3/4 NLRIs
in bgp_evpn.c and bgp_evpn_mh.c, and validates ENCAP/VNC
subtlv lengths in rfapi_rib.c to prevent crashes from
crafted BGP UPDATE messages.
CVE: CVE-2026-37460
Upstream patches:
- 7676cad651.patch
Resolves: RHEL-193235
This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.
Assisted-by: Ymir
This commit is contained in:
parent
5dd1b26602
commit
c859edd6ca
97
0020-fix-CVE-2026-37460.patch
Normal file
97
0020-fix-CVE-2026-37460.patch
Normal file
@ -0,0 +1,97 @@
|
||||
From 7c9a8cfc48b61708b758f9d0e3445f64c225e914 Mon Sep 17 00:00:00 2001
|
||||
From: Mark Stapp <mjs@cisco.com>
|
||||
Date: Wed, 11 Mar 2026 14:52:54 -0400
|
||||
Subject: [PATCH] bgpd: improve packet parsing for EVPN and ENCAP/VNC
|
||||
|
||||
Improve packet validation for EVPN NLRIs and for ENCAP/VNC.
|
||||
|
||||
Signed-off-by: Mark Stapp <mjs@cisco.com>
|
||||
---
|
||||
bgpd/bgp_evpn.c | 17 +++++++++++++++++
|
||||
bgpd/bgp_evpn_mh.c | 10 +++++++++-
|
||||
bgpd/rfapi/rfapi_rib.c | 9 +++++++++
|
||||
3 files changed, 35 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/bgpd/bgp_evpn.c b/bgpd/bgp_evpn.c
|
||||
index 2b2cfa0f4..e45bd46bf 100644
|
||||
--- a/bgpd/bgp_evpn.c
|
||||
+++ b/bgpd/bgp_evpn.c
|
||||
@@ -4505,6 +4505,14 @@ static int process_type2_route(struct peer *peer, afi_t afi, safi_t safi,
|
||||
goto fail;
|
||||
}
|
||||
|
||||
+ /* Validate ipaddr_len against the NLRI length */
|
||||
+ if ((psize != 33 + (ipaddr_len / 8)) && (psize != 36 + (ipaddr_len / 8))) {
|
||||
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
||||
+ "%u:%s - Rx EVPN Type-2 NLRI with invalid IP address length %d",
|
||||
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
||||
+ goto fail;
|
||||
+ }
|
||||
+
|
||||
if (ipaddr_len) {
|
||||
ipaddr_len /= 8; /* Convert to bytes. */
|
||||
p.prefix.macip_addr.ip.ipa_type = (ipaddr_len == IPV4_MAX_BYTELEN)
|
||||
@@ -4603,6 +4611,15 @@ static int process_type3_route(struct peer *peer, afi_t afi, safi_t safi,
|
||||
|
||||
/* Get the IP. */
|
||||
ipaddr_len = *pfx++;
|
||||
+
|
||||
+ /* Validate */
|
||||
+ if (psize != 13 + (ipaddr_len / 8)) {
|
||||
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
||||
+ "%u:%s - Rx EVPN Type-3 NLRI with invalid IP address length %d",
|
||||
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
||||
+ return -1;
|
||||
+ }
|
||||
+
|
||||
if (ipaddr_len == IPV4_MAX_BITLEN) {
|
||||
p.prefix.imet_addr.ip.ipa_type = IPADDR_V4;
|
||||
memcpy(&p.prefix.imet_addr.ip.ip.addr, pfx, IPV4_MAX_BYTELEN);
|
||||
diff --git a/bgpd/bgp_evpn_mh.c b/bgpd/bgp_evpn_mh.c
|
||||
index 552365959..548e9defe 100644
|
||||
--- a/bgpd/bgp_evpn_mh.c
|
||||
+++ b/bgpd/bgp_evpn_mh.c
|
||||
@@ -733,9 +733,17 @@ int bgp_evpn_type4_route_process(struct peer *peer, afi_t afi, safi_t safi,
|
||||
memcpy(&esi, pfx, ESI_BYTES);
|
||||
pfx += ESI_BYTES;
|
||||
|
||||
-
|
||||
/* Get the IP. */
|
||||
ipaddr_len = *pfx++;
|
||||
+
|
||||
+ /* Validate */
|
||||
+ if (psize != 19 + (ipaddr_len / 8)) {
|
||||
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
||||
+ "%u:%s - Rx EVPN Type-4 NLRI with invalid IP address length %d",
|
||||
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
||||
+ return -1;
|
||||
+ }
|
||||
+
|
||||
if (ipaddr_len == IPV4_MAX_BITLEN) {
|
||||
memcpy(&vtep_ip, pfx, IPV4_MAX_BYTELEN);
|
||||
} else {
|
||||
diff --git a/bgpd/rfapi/rfapi_rib.c b/bgpd/rfapi/rfapi_rib.c
|
||||
index a9c0c026e..71fcab0c3 100644
|
||||
--- a/bgpd/rfapi/rfapi_rib.c
|
||||
+++ b/bgpd/rfapi/rfapi_rib.c
|
||||
@@ -648,11 +648,20 @@ static void rfapiRibBi2Ri(struct bgp_path_info *bpi, struct rfapi_info *ri,
|
||||
break;
|
||||
|
||||
case BGP_VNC_SUBTLV_TYPE_RFPOPTION:
|
||||
+ /* Check for short subtlv: drop */
|
||||
+ if (pEncap->length < 3)
|
||||
+ break;
|
||||
+
|
||||
+ /* Length of zero not valid */
|
||||
+ if (pEncap->value[1] == 0)
|
||||
+ break;
|
||||
+
|
||||
hop = XCALLOC(MTYPE_BGP_TEA_OPTIONS,
|
||||
sizeof(struct bgp_tea_options));
|
||||
assert(hop);
|
||||
hop->type = pEncap->value[0];
|
||||
hop->length = pEncap->value[1];
|
||||
+
|
||||
hop->value = XCALLOC(MTYPE_BGP_TEA_OPTIONS_VALUE,
|
||||
pEncap->length - 2);
|
||||
assert(hop->value);
|
||||
7
frr.spec
7
frr.spec
@ -7,7 +7,7 @@
|
||||
|
||||
Name: frr
|
||||
Version: 8.5.3
|
||||
Release: 15%{?checkout}%{?dist}
|
||||
Release: 16%{?checkout}%{?dist}
|
||||
Summary: Routing daemon
|
||||
License: GPLv2+
|
||||
URL: http://www.frrouting.org
|
||||
@ -83,6 +83,7 @@ Patch0016: 0016-dont-ignore-kernel-route.patch
|
||||
Patch0017: 0017-fix-CVE-2026-37457.patch
|
||||
Patch0018: 0018-ignored-int-after-flapping.patch
|
||||
Patch0019: 0019-set-pythonnouser-env-var.patch
|
||||
Patch0020: 0020-fix-CVE-2026-37460.patch
|
||||
|
||||
%description
|
||||
FRRouting is free software that manages TCP/IP based routing protocols. It takes
|
||||
@ -290,6 +291,10 @@ make check PYTHON=%{__python3}
|
||||
%endif
|
||||
|
||||
%changelog
|
||||
* Tue Jul 21 2026 RHEL Packaging Agent <redhat-ymir-agent@redhat.com> - 8.5.3-16
|
||||
- Resolves: RHEL-193235 - CVE-2026-37460 frr: invalid EVPN/ENCAP packet
|
||||
parsing in bgpd
|
||||
|
||||
* Fri Jul 03 2026 Michal Ruprich <mruprich@redhat.com> - 8.5.3-15
|
||||
- Resolves: RHEL-176258 - AVC when reading user's site-packages
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user