Bug 2511524

Summary: CVE-2026-45103 opensips: SIP message smuggling via TCP Content-Length integer overflow [fedora-all]
Product: [Fedora] Fedora Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: opensipsAssignee: Peter Lemenkov <lemenkov>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: high    
Version: rawhideCC: lemenkov
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["61fa690c-65cd-46b7-838a-a449fb048115"]}
Fixed In Version: opensips-3.6.7-1.fc43 opensips-3.6.7-1.fc44 opensips-4.0.0-9.fc45 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-08-05 13:41:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2511284    

Description Guilherme de Almeida Suckevicz 2026-08-05 13:33:37 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

Comment 1 Peter Lemenkov 2026-08-05 13:41:15 UTC
OpenSIPS in Fedora is not affected — every active branch already carries the fix:

- rawhide/f45: opensips-4.0.0-9.fc45
- f44: opensips-3.6.7-1.fc44 (built 2026-06-24)
- f43: opensips-3.6.7-1.fc43 (built 2026-06-24)

There are no EPEL branches for this package, so the above is the full scope of [fedora-all].

Verified against upstream git rather than the advisory version claims. The Content-Length wraparound check was added by 4d23613b6 ("core: enforce bounds checks on input-derived lengths (#3888)"), which validates r->content_len against TCP_BUF_SIZE in net/proto_tcp/tcp_common.h before the value is used. git tag --contains places it in 3.6.6 and 3.6.7.

For 4.0.0 the corresponding master-branch commit was rebased, so hash containment is not meaningful there; the fix was instead confirmed by content — the "Content-Length value %d bigger than the reading buffer" guard is present in net/proto_tcp/tcp_common.h at tag 4.0.0.

Closing CURRENTRELEASE.