WireGuard Kernel Module Silently Overwrites AllowedIPs in Trie, Breaking Peer Routing Without Errors
The WireGuard kernel module does not preserve AllowedIPs entries for peers when duplicate prefixes are inserted. A server with multiple peers can lose routing information for earlier peers after a new peer is added with an overlapping AllowedIPs value, even though the on-disk configuration remains correct.
In the reported case, wg show displayed one peer with allowed ips: (none) while the other retained 10.100.0.0/24. The affected peer continued to complete handshakes and deliver inbound packets, yet outbound traffic failed after decryption, incrementing rx_frame_errors on the interface.
Root Cause in the AllowedIPs Trie
AllowedIPs are stored in a single struct allowedips trie belonging to the wg_device. Each peer holds only a list of back-references to trie nodes. When an exact match on both prefix and CIDR length occurs during insertion, the code executes:
- rcu_assign_pointer(node->peer, peer) — redirects the node to the new peer
- list_move_tail — removes the node from the previous peer’s allowedips_list
The operation returns success (0) with no warning, and neither wg nor wg-quick performs overlap checks.
Observed Symptoms and Affected Systems
The problem manifests differently depending on prefix length:
- Two peers with identical 10.100.0.0/24 — the first peer loses its entry
- One peer with 10.100.0.0/24 and another with 10.100.0.5/32 — both entries remain because lengths differ
Real-world reports include OpenWrt users adding mobile peers with 0.0.0.0/0, VyOS and OPNsense issues from 2020–2025, and Kubernetes clusters using Cilium or Calico where pod CIDRs are generated automatically.
Packet Handling and Diagnostics
Inbound packets from an orphaned peer are dropped after decryption with the message “Packet has unallowed src IP”, incrementing frame errors. Outbound packets to an address without a peer return ENOKEY (“Required key not available”) and increment tx_errors. Dynamic debug can surface the source-address message, but the overwrite itself produces no log entry.
The same trie-reassignment logic exists in wireguard-go, wireguard-nt, FreeBSD, and OpenBSD implementations, confirming the behavior is not Linux-specific.
Related articles
YApi Abandoned Since 2022: Fork Yapix Exposes Forgable Project Tokens and Critical Sandbox Flaws
YApi, a widely used open-source API documentation and mocking platform with 27.7k GitHub stars, has received no updates since its 1.12 release in November 2022. The project accumulated 1,629 open issues, including an unaddressed remote code execution report via mock scripts. Security researcher Perruer created the Yapix fork to address broken dependencies, Node.js 22 incompatibility with deprecated crypto.createCipher, and 244 known vulnerabilities in production dependencies. Analysis revealed that project tokens could be forged by any user because the default passsalt key was a hardcoded five-character string published on GitHub. The original implementation used vm2 and Node vm for script execution, both of which are unsafe, allowing arbitrary server-side code execution. Yapix migrates to isolated-vm with strict memory and time limits, replaces SHA-1 password hashing with scrypt, and blocks MongoDB operator injection in API parameters.
Researchers Bypass RP2350 Secure Debug Lock with Laser Fault Injection and Photon Emission Microscopy
Security researchers have demonstrated a hardware attack that restores Secure Debug access on the RP2350 microcontroller revision A4 despite permanent OTP fuses disabling it. Using photon emission microscopy they first located the exact physical bits of the DEBUGEN register, then applied precisely timed 980 nm laser pulses to flip two critical bits and re-enable the Mem-AP ports. The attack requires decapping the chip from the backside and laboratory equipment costing around $250,000, but succeeds in seconds once calibrated. It bypasses the CRIT1.DEBUG_DISABLE fuse, TrustZone restrictions, and glitch detectors by resetting the device before firmware can re-lock the OTP page. The technique was developed against the updated A4 silicon released after the first Raspberry Pi Hacking Challenge. The work highlights that even heavily hardened microcontrollers remain vulnerable to sophisticated physical attacks when an attacker has direct silicon access.
ServiceNow AI Platform Affected by Five Vulnerabilities Including Critical SQL Injection Flaws
ServiceNow disclosed five vulnerabilities in its AI Platform on September 24, 2026, through a security advisory. Two of the issues received CVSS v4.0 base scores of 9.3 and were rated Critical. CVE-2026-13016 allows unauthenticated remote attackers to perform SQL injection and manipulate database contents under specific conditions. CVE-2026-86860 stems from improper authorization checks that enable data exfiltration and privilege escalation without authentication. The flaws were identified via internal testing, coordinated disclosure, and the company's bug bounty program. ServiceNow urges customers to apply the provided updates immediately to mitigate the risks.
CISA Adds Adobe Commerce and WSO2 Vulnerabilities to Known Exploited Vulnerabilities Catalog
The US Cybersecurity and Infrastructure Security Agency has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog. CVE-2026-71362 affects Adobe Commerce and Magento, enabling attackers to escalate privileges through an authorization bypass flaw. CVE-2026-5430 impacts multiple WSO2 API management products and allows JWT authentication bypass, leading to administrator account takeover and remote code execution via arbitrary file uploads. Adobe issued an advisory in August 2026 recommending patches within 30 days, while WSO2 warned about the issue in May 2026. CISA has set a September 27, 2026 deadline for federal agencies to apply updates and investigate potential compromises.