CVE-2023-38406: Critical severity frrouting bgpd vulnerability
Published Nov 6, 2023
·Updated
bgpd/bgpflowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
Affected Software
3 affected componentsFixes available
redhat/ffr<8.4.3
8.4.3
Frrouting FRRouting<8.4.3
debian/frr<=7.5.1-1.1+deb11u2
7.5.1-1.1+deb11u48.4.4-1.1~deb12u110.2.1-2
Remediation
Patch Available
Patch Available
Event History
Nov 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 13, 2024
Data Sourced
via Ubuntu·06:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-38406.
2
What is the severity of CVE-2023-38406?
CVE-2023-38406 has a severity rating of 9.8 (Critical).
3
What software is affected by CVE-2023-38406?
Frrouting Frrouting versions up to 8.4.3 are affected by CVE-2023-38406.
4
What is the description of CVE-2023-38406?
CVE-2023-38406 is a vulnerability in bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3, which mishandles an nlri length of zero, leading to a flowspec overflow.
5
How can I fix CVE-2023-38406?
To fix CVE-2023-38406, you should update your Frrouting Frrouting software to version 8.4.3 or later.