CVE-2021-26928
NixOS vulnerability analysis and mitigation

Overview

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. This vulnerability was discovered in June 2021 and is tracked as CVE-2021-26928. The vulnerability is disputed as Tigera disagrees that the behavior is within their area of responsibility (CyberArk Research).

Technical details

The vulnerability stems from BIRD's lack of password authentication functionality for BGP peers, which could allow an attacker to hijack BGP sessions. The attack involves stealing TCP sessions and manipulating BGP routing updates by sending forged NEXT_HOP values with more specific subnets. The vulnerability also leverages a logical flaw in BGP RFC4724 that enables persistent BGP hijacking through capability downgrade attacks (CyberArk Research).

Impact

The vulnerability could allow attackers to perform route redirection attacks leading to denial of service and/or information disclosure. An attacker who successfully exploits this vulnerability could place themselves in a man-in-the-middle position within the cluster, potentially intercepting and manipulating network traffic between pods (CyberArk Research).

Exploitability

The vulnerability requires a low-privileged user access on a node (master/worker) or on a pod with host network namespace. This could be achieved through various attack vectors such as running an RCE on a node's SCOM agent or accessing a pod with HostNetwork configured. The attack can be executed using simple network tools and crafted BGP messages (CyberArk Research).

Mitigation and workarounds

Several mitigation steps are recommended: 1) Ensure pods are properly configured and not using HostNetwork mode unless necessary 2) Drop NET_RAW capability from pod settings to prevent packet manipulation 3) Implement TCP-MD5 authentication for BGP peers 4) Keep node OS and third-party software up to date. Tigera has released a fix in Calico v3.16.3 that allows users to configure a password to authenticate BGP peers (CyberArk Research).

Community reactions

The vulnerability led to disagreement between CyberArk Labs and Tigera regarding the nature of the vulnerability. While CyberArk Labs identified it as a design issue in Tigera's implementation, Tigera maintained that it was a flaw in the BGP protocol behavior. This resulted in the CVE being marked as disputed (CyberArk Research).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • cilium-fips-1.20
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-fips-4.0
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management