First published: Thu Oct 26 2023(Updated: )
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/frr | <9.0.1 | 9.0.1 |
Frrouting Frrouting | <=9.0.1 | |
debian/frr | <=7.5.1-1.1+deb11u2<=8.4.4-1.1~deb12u1 | 7.5.1-1.1+deb11u3 10.2.1-1 10.2.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46753 is a vulnerability in FRRouting FRR through version 9.0.1 that can result in a crash when receiving a crafted BGP UPDATE message without mandatory attributes.
CVE-2023-46753 has a severity level of high with a CVSS score of 7.5.
CVE-2023-46753 affects FRRouting versions up to and including 9.0.1.
There is no known fix for CVE-2023-46753 at the moment. It is recommended to monitor the project's official website for updates or patches.
You can find more information about CVE-2023-46753 on the GitHub page for FRRouting's pull request #14645.