BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a sufficient message length causes a four-byte overflow to occur while processing the message, where two of the overflow bytes are attacker-controlled and two are fixed.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "10.0"
},
{
"last_affected": "10.0"
}
],
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "debian:debian_linux"
},
{
"extracted_events": [
{
"introduced": "29"
},
{
"last_affected": "29"
},
{
"introduced": "30"
},
{
"last_affected": "30"
}
],
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "fedoraproject:fedora"
},
{
"extracted_events": [
{
"introduced": "15.0-sp1"
},
{
"last_affected": "15.0-sp1"
}
],
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"source": "CPE_STRING",
"vendor_product": "opensuse:backports_sle"
}
]
}{
"cpe": "cpe:2.3:a:nic:bird:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.6.0"
},
{
"last_affected": "1.6.7"
},
{
"introduced": "2.0.0"
},
{
"last_affected": "2.0.5"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-08T17:18:14Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"216893417837476986888965276365877246422",
"223445219091451626815491961387763006748",
"321385252695183225000492290604323630133",
"240393356610038048681844503473819906720",
"4383943790272205345412568721163061337",
"276441775111768339359338816026274139390",
"84258977817401017440276937716070434403",
"295253454909988706774094035716076630568"
]
},
"signature_version": "v1",
"source": "https://gitlab.nic.cz/labs/bird@8388f5a7e14108a1458fea35bfbb5a453e2c563c",
"id": "CVE-2019-16159-19bde9a3",
"target": {
"file": "proto/bgp/packets.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 448.0,
"function_hash": "130779972019287339614087948162341524144"
},
"signature_version": "v1",
"source": "https://gitlab.nic.cz/labs/bird@8388f5a7e14108a1458fea35bfbb5a453e2c563c",
"id": "CVE-2019-16159-62d9e0ec",
"target": {
"function": "bgp_handle_message",
"file": "proto/bgp/packets.c"
}
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"216893417837476986888965276365877246422",
"223445219091451626815491961387763006748",
"321385252695183225000492290604323630133",
"240393356610038048681844503473819906720",
"255920384722461930579550090089086617062",
"38099894567800398323843450381818194066",
"84125401342413400062944322038071946879",
"70697898021381015989562920937856652083"
]
},
"signature_version": "v1",
"source": "https://gitlab.nic.cz/labs/bird@1657c41c96b3c07d9265b07dd4912033ead4124b",
"id": "CVE-2019-16159-c1c649bd",
"target": {
"file": "proto/bgp/packets.c"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 448.0,
"function_hash": "130779972019287339614087948162341524144"
},
"signature_version": "v1",
"source": "https://gitlab.nic.cz/labs/bird@1657c41c96b3c07d9265b07dd4912033ead4124b",
"id": "CVE-2019-16159-ffdc3bfd",
"target": {
"function": "bgp_handle_message",
"file": "proto/bgp/packets.c"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16159.json"