First published: Mon Nov 06 2023(Updated: )
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ffr | <8.4.3 | 8.4.3 |
Frrouting Frrouting | <8.4.3 | |
debian/frr | <=7.5.1-1.1+deb11u2 | 7.5.1-1.1+deb11u3 8.4.4-1.1~deb12u1 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-38406.
CVE-2023-38406 has a severity rating of 9.8 (Critical).
Frrouting Frrouting versions up to 8.4.3 are affected by CVE-2023-38406.
CVE-2023-38406 is a vulnerability in bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3, which mishandles an nlri length of zero, leading to a flowspec overflow.
To fix CVE-2023-38406, you should update your Frrouting Frrouting software to version 8.4.3 or later.