Skip to content

Conversation

oliverchang
Copy link
Contributor

@oliverchang oliverchang commented Jul 31, 2025

Fixed a stack buffer overflow in
zread_srv6_manager_release_locator_chunk and
zread_srv6_manager_get_locator_chunk by adding a check to ensure the length read from the stream does not exceed the stack buffer size.

https://oss-fuzz.com/testcase-detail/5455147614994432
https://issues.oss-fuzz.com/issues/42504504

Fixed a stack buffer overflow in
`zread_srv6_manager_release_locator_chunk` and
`zread_srv6_manager_get_locator_chunk` by adding a check to ensure the
length read from the stream does not exceed the stack buffer size.

https: //oss-fuzz.com/testcase-detail/5455147614994432
https: //issues.oss-fuzz.com/issues/42504504
Change-Id: Ib28a49ca0a034542a45f25a15c5588ad5310f0ac
Signed-off-by: Oliver Chang <ochang@google.com>
@ton31337
Copy link
Member

@Mergifyio backport stable/10.4 stable/10.3 stable/10.2 stable/10.1

Copy link

mergify bot commented Jul 31, 2025

backport stable/10.4 stable/10.3 stable/10.2 stable/10.1

✅ Backports have been created

@ton31337 ton31337 merged commit e273036 into FRRouting:master Jul 31, 2025
14 checks passed
donaldsharp added a commit that referenced this pull request Jul 31, 2025
zebra: Fix buffer overflows found by fuzzing. (backport #19303)
donaldsharp added a commit that referenced this pull request Jul 31, 2025
zebra: Fix buffer overflows found by fuzzing. (backport #19303)
donaldsharp added a commit that referenced this pull request Jul 31, 2025
zebra: Fix buffer overflows found by fuzzing. (backport #19303)
donaldsharp added a commit that referenced this pull request Jul 31, 2025
zebra: Fix buffer overflows found by fuzzing. (backport #19303)
Jafaral added a commit that referenced this pull request Aug 2, 2025
Bug Fixes:

* bgpd: initialize local variable (backport #19233)
* ospfd: Use after free cleanup of lsa (backport #19224)
* vtysh: copy config from file should actually apply (backport #19242)
* Revert PR #18358: BGP evpn testing and bug fixes related to non default EVPN backbone  (backport #19241)
* topotests: improve embedded RP test reliability (backport #19240)
* lib, zebra: mark singleton nexthops inactive/active on link state changes for wecmp (backport #18947)
* bgpd: LL next-hop capabilty fixes (backport #19261)
* eigrp: validate hello packets and tlvs better (backport #19251)
* bgpd: Fix compilation error in bgpd module: Update TP_ARGS for bgp (backport #19266)
* bgpd: Ensure addpath does not withdraw selected route in some situations (backport #19210)
* bgpd: [GR] fixed selectionDeferralTimer to display select_defer_time val by #19282
* bgpd: LL next-hop capabilty fixes (round 2) (backport #19277)
* lib: compute link-state zapi message size (backport #19290)
* zebra: Fix buffer overflows found by fuzzing. (backport #19303)

Signed-off-by: Jafar Al-Gharaibeh <jafar@atcorp.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants