First published: Thu Oct 26 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/frr | <9.0.1 | 9.0.1 |
Frrouting Frrouting | <=9.0.1 | |
debian/frr | <=7.5.1-1.1+deb11u2<=8.4.4-1.1~deb12u1 | 7.5.1-1.1+deb11u3 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46752 is a vulnerability in FRRouting FRR through version 9.0.1 that mishandles malformed MP_REACH_NLRI data, causing a crash.
CVE-2023-46752 affects Frrouting Frrouting versions up to and including 9.0.1.
The severity of CVE-2023-46752 is high, with a CVSS score of 7.5.
To fix CVE-2023-46752, it is recommended to update to a version of Frrouting Frrouting that is beyond 9.0.1.
More information about CVE-2023-46752 can be found at the following reference link: [GitHub Reference](https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35).