CVE-2023-41360: Critical severity frrouting bgpd vulnerability
Published Aug 29, 2023
·Updated
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgppacket.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Affected Software
14 affected componentsFixes available
debian/frr
7.5.1-1.1+deb10u17.5.1-1.1+deb11u28.4.4-1.1~deb12u19.1-0.1
ubuntu/frr<7.2.1-1ubuntu0.2+
7.2.1-1ubuntu0.2+
ubuntu/frr<8.1-1ubuntu1.6
8.1-1ubuntu1.6
ubuntu/frr<8.4.2-1ubuntu1.4
8.4.2-1ubuntu1.4
ubuntu/quagga<1.2.4-1ubuntu0.1~
1.2.4-1ubuntu0.1~
ubuntu/quagga<1.2.4-4ubuntu0.1
1.2.4-4ubuntu0.1
ubuntu/quagga<0.99.24.1-2ubuntu1.4+
0.99.24.1-2ubuntu1.4+
redhat/frr<9.1
9.1
redhat/frr<8.5
8.5
Frrouting FRRouting<=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Remediation
Patch Available
Event History
Aug 29, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Jan 12, 2024
Data Sourced
via Launchpad·12:25 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-41360?
The severity of CVE-2023-41360 is critical with a severity score of 9.1.
2
How does CVE-2023-41360 affect FRRouting?
CVE-2023-41360 affects FRRouting versions up to and including 9.0.
3
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-41360?
The CWE ID for CVE-2023-41360 is CWE-125.
4
How can I fix CVE-2023-41360?
To fix CVE-2023-41360, it is recommended to update FRRouting to a version higher than 9.0.
5
Where can I find more information about CVE-2023-41360?
You can find more information about CVE-2023-41360 in the following references: - [GitHub](https://github.com/FRRouting/frr/pull/14245) - [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html)