[Buildroot] [PATCH] quagga: add upstream security fix for CVE-2017-16227

Thomas Petazzoni thomas.petazzoni at free-electrons.com
Wed Nov 1 09:47:23 UTC 2017


Hello,

On Mon, 30 Oct 2017 22:53:09 +0100, Peter Korsgaard wrote:
> From the advisory:
> http://www.openwall.com/lists/oss-security/2017/10/30/4
> 
> It was discovered that the bgpd daemon in the Quagga routing suite does
> not properly calculate the length of multi-segment AS_PATH UPDATE
> messages, causing bgpd to drop a session and potentially resulting in
> loss of network connectivity.
> 
> Signed-off-by: Peter Korsgaard <peter at korsgaard.com>
> ---
>  ...x-AS_PATH-size-calculation-for-long-paths.patch | 33 ++++++++++++++++++++++
>  1 file changed, 33 insertions(+)
>  create mode 100644 package/quagga/0004-bgpd-Fix-AS_PATH-size-calculation-for-long-paths.patch

Applied to master, thanks.

Thomas
-- 
Thomas Petazzoni, CTO, Free Electrons
Embedded Linux, Kernel and Android engineering
http://free-electrons.com


More information about the buildroot mailing list