Bug 2511524 - CVE-2026-45103 opensips: SIP message smuggling via TCP Content-Length integer overflow [fedora-all]
Summary: CVE-2026-45103 opensips: SIP message smuggling via TCP Content-Length integer...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: opensips
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Peter Lemenkov
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["61fa690c-65cd-46b7-838a-a...
Depends On:
Blocks: CVE-2026-45103
TreeView+ depends on / blocked
 
Reported: 2026-08-05 13:33 UTC by Guilherme de Almeida Suckevicz
Modified: 2026-08-05 13:41 UTC (History)
1 user (show)

Fixed In Version: opensips-3.6.7-1.fc43 opensips-3.6.7-1.fc44 opensips-4.0.0-9.fc45
Clone Of:
Environment:
Last Closed: 2026-08-05 13:41:15 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2026-08-05 13:33:37 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arithmetic with no overflow check. When an attacker sends a Content-Length value that overflows unsigned int (e.g., 4294967296), the framing layer computes a wrapped-around value (e.g., 0) and splits the TCP stream at the wrong boundary, causing the body of the first SIP message to be processed as a separate message and enabling SIP message smuggling. Because Content-Length is parsed in the transport layer before authentication, an unauthenticated, network-based attacker can smuggle arbitrary SIP messages over any TCP-based transport (proto_tcp, proto_tls, proto_ws, proto_wss) on any instance with TCP enabled, with no routing-script preconditions. This allows smuggled messages to bypass front-end SBC/proxy security policies, inherit the connection's authentication context, and evade rate limiting. This issue has been fixed in versions 3.6.6 and 4.0.0-rc1.

Comment 1 Peter Lemenkov 2026-08-05 13:41:15 UTC
OpenSIPS in Fedora is not affected — every active branch already carries the fix:

- rawhide/f45: opensips-4.0.0-9.fc45
- f44: opensips-3.6.7-1.fc44 (built 2026-06-24)
- f43: opensips-3.6.7-1.fc43 (built 2026-06-24)

There are no EPEL branches for this package, so the above is the full scope of [fedora-all].

Verified against upstream git rather than the advisory version claims. The Content-Length wraparound check was added by 4d23613b6 ("core: enforce bounds checks on input-derived lengths (#3888)"), which validates r->content_len against TCP_BUF_SIZE in net/proto_tcp/tcp_common.h before the value is used. git tag --contains places it in 3.6.6 and 3.6.7.

For 4.0.0 the corresponding master-branch commit was rebased, so hash containment is not meaningful there; the fix was instead confirmed by content — the "Content-Length value %d bigger than the reading buffer" guard is present in net/proto_tcp/tcp_common.h at tag 4.0.0.

Closing CURRENTRELEASE.


Note You need to log in before you can comment on or make changes to this bug.