Closed ErodedElk closed 8 months ago
in /ryu/ofproto/ofproto_v1_3_parser.py about line=2922 in /ryu/ofproto/ofproto_v1_4_parser.py about line=4586 in /ryu/ofproto/ofproto_v1_3_parser.py about line=5454
There may be no clear path to trigger this vulnerability. The previous payload originated from https://github.com/faucetsdn/ryu/issues/188.
in /ryu/ofproto/ofproto_v1_3_parser.py about line=2922
If OFPAction.len=0,the offset will no longer change and the parsing will fall into an infinite loop.
This message will put ryu into an infinite loop:
poc: