Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
Link | Tags |
---|---|
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling | third party advisory exploit |
https://news.ycombinator.com/item?id=37305800 | issue tracking |
https://www.nokia.com/networks/technologies/service-router-operating-system/ | product |