Описание
Security update for radvd
This update for radvd fixes the following issue
- CVE-2026-48715: stack-based buffer overflow in the
radvdumpRoute Information option parser when processing crafted ICMPv6 Router Advertisements (bsc#1268641).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server 15 SP4-LTSS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server 15 SP5-LTSS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server 15 SP6-LTSS
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
radvd-2.17-150000.5.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
radvd-2.17-150000.5.8.1
Ссылки
- Link for SUSE-SU-2026:3055-1
- E-Mail link for SUSE-SU-2026:3055-1
- SUSE Security Ratings
- SUSE Bug 1268641
- SUSE CVE CVE-2026-48715 page
Описание
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 patches the issue.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS:radvd-2.17-150000.5.8.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS:radvd-2.17-150000.5.8.1
Ссылки
- CVE-2026-48715
- SUSE Bug 1268641