CVE-2021-27861: L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with invalid lengths
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length (and optionally VLAN0 headers)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-27861?
CVE-2021-27861 is a vulnerability that allows bypassing layer 2 network filtering capabilities such as IPv6 RA guard by using LLC/SNAP headers with invalid length.
How can the layer 2 network filtering capabilities be bypassed?
The layer 2 network filtering capabilities can be bypassed by using LLC/SNAP headers with invalid length and optionally VLAN0 headers.
Which software is affected by CVE-2021-27861?
The vulnerability affects IEEE 802.2 (up to and including version 802.2h-1997) and IETF P802.1q (up to and including version d1.0).
What is the severity of CVE-2021-27861?
The severity of CVE-2021-27861 is medium with a severity value of 4.7.
How can I fix CVE-2021-27861?
To fix CVE-2021-27861, it is recommended to update the affected software to a version that addresses the vulnerability.