this post was submitted on 22 Mar 2022
9 points (100.0% liked)

OpenBSD Operating System

532 readers
2 users here now

useful resources:

Developer blogs:

Ressources:

founded 4 years ago
MODERATORS
 

In this blog post we analyze a heap overflow vulnerability we discovered in the IPv6 stack of OpenBSD, more specifically in its slaacd daemon. This issue, whose root cause can be found in the mishandling of Router Advertisement messages containing a DNSSL option with a malformed domain label, was patched by OpenBSD on March 21, 2022. A proof-of-concept to reproduce the vulnerability is provided.

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here