CVE-2023-38802: High severity frrouting bgpd vulnerability
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Other sources
Incorrect length handling of path attributes in BGP packets can lead to a session reset.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-38802?
CVE-2023-38802 is a vulnerability in FRRouting and Pica8 PICOS that allows a remote attacker to cause a denial of service by exploiting a corrupted attribute in a BGP update packet.
How does CVE-2023-38802 impact FRRouting?
CVE-2023-38802 affects FRRouting versions 7.5.1 through 9.0 and can lead to a denial of service attack.
How does CVE-2023-38802 impact Pica8 PICOS?
CVE-2023-38802 affects Pica8 PICOS version 4.3.3.2 and can lead to a denial of service attack.
How can I fix CVE-2023-38802 in FRRouting?
To fix CVE-2023-38802 in FRRouting, update to a version that is not affected, such as 9.0 or a later version, once it becomes available.
How can I fix CVE-2023-38802 in Pica8 PICOS?
To fix CVE-2023-38802 in Pica8 PICOS, update to version 4.3.3.3 or a later version, once it becomes available.