[+ Jim: the draft is in IETF LC.]

Sasha:

Yes, the risk you describe is a BGP attack that could affect SRv6 services.

§6.3 covers this topic (deletion/modification), but doesn’t mention your
specific example — it can’t list them all!  I’ll leave it to the authors.

Thanks!

Alvaro.

On September 4, 2026 at 3:14:01 AM, Alexander Vainshtein (
[email protected]) wrote:

Hi all,
I have briefly looked up the current version of the draft.

I am not a security expert, but it seems that the draft deals with security
aspects of SRv6 *underlay. *
I wonder if SRv6 "service SIDs" and the way they are advertised in BGP do
not introduce any special vulnerabilities.

E.g., a compromised Route Reflector could modify (or simply discard) the
BGP Prefix SID Attribute in routes of such families as VPN-IP or EVPN -
with a devastating effect on the services., while such an attack would not
have any impact on IP-VPN and EVPN services over MPLS underlay.

What, if anything, do I miss?

Regards,
Sasha


Get Outlook for Android <https://aka.ms/AAb9ysg>


*Disclaimer*

This e-mail together with any attachments may contain information of Ribbon
Communications Inc. and its Affiliates that is confidential and/or
proprietary for the sole use of the intended recipient. Any review,
disclosure, reliance or distribution by others or forwarding without
express permission is strictly prohibited. If you are not the intended
recipient, please notify the sender immediately and then delete all copies,
including any attachments.
_______________________________________________
BESS mailing list -- [email protected]
To unsubscribe send an email to [email protected]
_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to