Gnoppix Security Update: Bird BGP Daemon Fixes Critical Crash Bug
Gnoppix issued a security update for Bird (GSA-6347-1), patching a critical flaw in the BGP routing daemon that could cause it to crash.
A malformed BGP OPEN message triggers an assertion failure, crashing the bird2 service. This results in a denial of service for network routing.
Affected Systems
All systems running bird2 on Gnoppix 23/25 (oldstable) and Gnoppix 25 (stable).
Recommended Action
Immediately upgrade the bird2 package to the patched version for your distribution.
Vulnerability Details
The flaw occurs during BGP session establishment. A crafted packet from an attacker forces the daemon to fail an internal assertion.
System administrators should treat this update as high priority to prevent routing outages.
Technical Background
Bird is an open-source BGP daemon widely used for internet routing. The bug was introduced in recent code changes affecting BGP OPEN message parsing.
The update includes backported fixes to both stable and oldstable releases. No workarounds exist besides applying the patch. - Please update your systems.