Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <ah62-ZU9c_cEa8f0@symphytum.spacehopper.org>
Date: Tue, 2 Jun 2026 11:56:57 +0100
From: Stuart Henderson <stu@...cehopper.org>
To: oss-security@...ts.openwall.com
Subject: Re: BIRD/BIRD2: stack buffer overflow in BGP AS_PATH
 mask matching, CVE pending

On 2026/06/02 10:07, Bakabaka_9 wrote:
> Tested affected:
> 
> - BIRD 2.16.2
> 
> Possibly affected:
> 
> - Other BIRD 2.x versions using the same AS_PATH mask matching
>   implementation.
> 
> Not affected:
> 
> - Unknown.
> 
> Fixed version
> =============
> 
> No fixed version is available at the time of this disclosure.

If you've only tried one version from April 2025, how can you can say
with certainty that it's not been fixed since then?

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.