First published: Tue Aug 29 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frrouting Frrouting | <=9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Fedoraproject Fedora | =39 | |
debian/frr | <=6.0.2-2+deb10u1 | 7.5.1-1.1+deb10u1 7.5.1-1.1+deb11u2 8.4.4-1.1~deb12u1 9.1-0.1 |
ubuntu/frr | <7.2.1-1ubuntu0.2+ | 7.2.1-1ubuntu0.2+ |
ubuntu/frr | <8.1-1ubuntu1.6 | 8.1-1ubuntu1.6 |
ubuntu/frr | <8.4.2-1ubuntu1.4 | 8.4.2-1ubuntu1.4 |
ubuntu/quagga | <1.2.4-1ubuntu0.1~ | 1.2.4-1ubuntu0.1~ |
ubuntu/quagga | <1.2.4-4ubuntu0.1 | 1.2.4-4ubuntu0.1 |
ubuntu/quagga | <0.99.24.1-2ubuntu1.4+ | 0.99.24.1-2ubuntu1.4+ |
redhat/frr | <9.1 | 9.1 |
redhat/frr | <8.5 | 8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41358 is a vulnerability in FRRouting FRR versions up to 9.0 that allows remote attackers to cause a denial of service (crash) via a crafted attribute length of 0 in a BGP packet.
CVE-2023-41358 has a severity rating of high, with a CVSS score of 7.5.
CVE-2023-41358 affects FRRouting FRR versions up to 9.0.
Yes, the fix for CVE-2023-41358 is available in FRRouting FRR version 9.0 or later.
You can find more information about CVE-2023-41358 in the following references: [link1](https://github.com/FRRouting/frr/pull/14260), [link2](https://github.com/FRRouting/frr/commit/28ccc24d38df1d51ed8a563507e5d6f6171fdd38), [link3](https://github.com/FRRouting/frr/pull/14270).