|
|
Message-ID: <11FDE3F9-1393-4AC0-B078-52E2DA316480@lightwave.net.ru> Date: Wed, 03 Jun 2026 00:50:02 +0300 From: Dan Yefihmov <dan@...htwave.net.ru> To: oss-security@...ts.openwall.com Subject: Re: BIRD/BIRD2: stack buffer overflow in BGP AS_PATH mask matching, CVE pending On June 2, 2026 11:41:33 PM GMT+03:00, Stuart Henderson <stu@...cehopper.org> wrote: >>From the talk I linked to, for BIRD from the start of 2026 up to 19 May, >that was *70*. The ones I've seen (not for BIRD) they're often extremely >verbose, and they're often plain wrong (the talk suggests ~ 9% of the >reports for BIRD were valid). > >At this point I think it is fairly reasonable for small development >teams to not spend all that much time researching a lower-effort >report. If it's valid there will likely be a handful of duplicate >reports coming along soon afterwards anyway, and hopefully one of >those may have done more triage before sending out. > If somebody writes he doesn't currently plan to do something, that means only that, nothing else. Everything else is a pure speculation, not an established fact. Sincerely Yours, Dan.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.