Actions
Bug #7753
openvxlan: decoder drops packets with non-zero reserved fields
Affected Versions:
Effort:
Difficulty:
Label:
C, Needs Suricata-Verify test, Protocol
Description
The current VXLAN decoder implementation follows RFC draft-mahalingam-dutt-dcops-vxlan-00 too strictly and does not ignore the Reserved fields on receipt, as required by RFC 7348 §5 . This causes valid VXLAN packets with non-zero Reserved bits to be dropped, leading to loss of response-side traffic in some environments.
Files
Actions