98 lines
3.1 KiB
Diff
98 lines
3.1 KiB
Diff
From 88b969896c6a594b4507c58bf44d8914967838f2 Mon Sep 17 00:00:00 2001
|
|
From: Mark Stapp <mjs@cisco.com>
|
|
Date: Wed, 11 Mar 2026 14:52:54 -0400
|
|
Subject: [PATCH] bgpd: improve packet parsing for EVPN and ENCAP/VNC
|
|
|
|
Improve packet validation for EVPN NLRIs and for ENCAP/VNC.
|
|
|
|
Signed-off-by: Mark Stapp <mjs@cisco.com>
|
|
---
|
|
bgpd/bgp_evpn.c | 17 +++++++++++++++++
|
|
bgpd/bgp_evpn_mh.c | 10 +++++++++-
|
|
bgpd/rfapi/rfapi_rib.c | 9 +++++++++
|
|
3 files changed, 35 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/bgpd/bgp_evpn.c b/bgpd/bgp_evpn.c
|
|
index fa4145cf7e..366c008d8e 100644
|
|
--- a/bgpd/bgp_evpn.c
|
|
+++ b/bgpd/bgp_evpn.c
|
|
@@ -3689,6 +3689,14 @@ static int process_type2_route(struct peer *peer, afi_t afi, safi_t safi,
|
|
goto fail;
|
|
}
|
|
|
|
+ /* Validate ipaddr_len against the NLRI length */
|
|
+ if ((psize != 33 + (ipaddr_len / 8)) && (psize != 36 + (ipaddr_len / 8))) {
|
|
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
|
+ "%u:%s - Rx EVPN Type-2 NLRI with invalid IP address length %d",
|
|
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
|
+ goto fail;
|
|
+ }
|
|
+
|
|
if (ipaddr_len) {
|
|
ipaddr_len /= 8; /* Convert to bytes. */
|
|
p.prefix.macip_addr.ip.ipa_type = (ipaddr_len == IPV4_MAX_BYTELEN)
|
|
@@ -3786,6 +3794,15 @@ static int process_type3_route(struct peer *peer, afi_t afi, safi_t safi,
|
|
|
|
/* Get the IP. */
|
|
ipaddr_len = *pfx++;
|
|
+
|
|
+ /* Validate */
|
|
+ if (psize != 13 + (ipaddr_len / 8)) {
|
|
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
|
+ "%u:%s - Rx EVPN Type-3 NLRI with invalid IP address length %d",
|
|
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
|
+ return -1;
|
|
+ }
|
|
+
|
|
if (ipaddr_len == IPV4_MAX_BITLEN) {
|
|
p.prefix.imet_addr.ip.ipa_type = IPADDR_V4;
|
|
memcpy(&p.prefix.imet_addr.ip.ip.addr, pfx, IPV4_MAX_BYTELEN);
|
|
diff --git a/bgpd/bgp_evpn_mh.c b/bgpd/bgp_evpn_mh.c
|
|
index e47a4d6507..6318aaa4ec 100644
|
|
--- a/bgpd/bgp_evpn_mh.c
|
|
+++ b/bgpd/bgp_evpn_mh.c
|
|
@@ -652,9 +652,17 @@ int bgp_evpn_type4_route_process(struct peer *peer, afi_t afi, safi_t safi,
|
|
memcpy(&esi, pfx, ESI_BYTES);
|
|
pfx += ESI_BYTES;
|
|
|
|
-
|
|
/* Get the IP. */
|
|
ipaddr_len = *pfx++;
|
|
+
|
|
+ /* Validate */
|
|
+ if (psize != 19 + (ipaddr_len / 8)) {
|
|
+ flog_err(EC_BGP_EVPN_ROUTE_INVALID,
|
|
+ "%u:%s - Rx EVPN Type-4 NLRI with invalid IP address length %d",
|
|
+ peer->bgp->vrf_id, peer->host, ipaddr_len);
|
|
+ return -1;
|
|
+ }
|
|
+
|
|
if (ipaddr_len == IPV4_MAX_BITLEN) {
|
|
memcpy(&vtep_ip, pfx, IPV4_MAX_BYTELEN);
|
|
} else {
|
|
diff --git a/bgpd/rfapi/rfapi_rib.c b/bgpd/rfapi/rfapi_rib.c
|
|
index e068eb7af6..db96970032 100644
|
|
--- a/bgpd/rfapi/rfapi_rib.c
|
|
+++ b/bgpd/rfapi/rfapi_rib.c
|
|
@@ -634,11 +634,20 @@ static void rfapiRibBi2Ri(struct bgp_path_info *bpi, struct rfapi_info *ri,
|
|
break;
|
|
|
|
case BGP_VNC_SUBTLV_TYPE_RFPOPTION:
|
|
+ /* Check for short subtlv: drop */
|
|
+ if (pEncap->length < 3)
|
|
+ break;
|
|
+
|
|
+ /* Length of zero not valid */
|
|
+ if (pEncap->value[1] == 0)
|
|
+ break;
|
|
+
|
|
hop = XCALLOC(MTYPE_BGP_TEA_OPTIONS,
|
|
sizeof(struct bgp_tea_options));
|
|
assert(hop);
|
|
hop->type = pEncap->value[0];
|
|
hop->length = pEncap->value[1];
|
|
+
|
|
hop->value = XCALLOC(MTYPE_BGP_TEA_OPTIONS_VALUE,
|
|
pEncap->length - 2);
|
|
assert(hop->value);
|