CVE-2023-41358: Null Pointer Dereference
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgppacket.c processes NLRIs if the attribute length is zero.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-41358?
CVE-2023-41358 is a vulnerability in FRRouting FRR versions up to 9.0 that allows remote attackers to cause a denial of service (crash) via a crafted attribute length of 0 in a BGP packet.
How severe is CVE-2023-41358?
CVE-2023-41358 has a severity rating of high, with a CVSS score of 7.5.
How does CVE-2023-41358 affect the FRRouting software?
CVE-2023-41358 affects FRRouting FRR versions up to 9.0.
Is there a fix for CVE-2023-41358?
Yes, the fix for CVE-2023-41358 is available in FRRouting FRR version 9.0 or later.
Where can I find more information about CVE-2023-41358?
You can find more information about CVE-2023-41358 in the following references: [link1](https://github.com/FRRouting/frr/pull/14260), [link2](https://github.com/FRRouting/frr/commit/28ccc24d38df1d51ed8a563507e5d6f6171fdd38), [link3](https://github.com/FRRouting/frr/pull/14270).