CVE-2024-31948: Medium severity debian/frr vulnerability
Published Apr 7, 2024
·Updated
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
Affected Software
2 affected componentsFixes available
debian/frr<=7.5.1-1.1+deb11u2, <=8.4.4-1.1~deb12u1
7.5.1-1.1+deb11u410.2.1-2
Frrouting FRRouting<=9.1
Remediation
Event History
Apr 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyAffected Software
May 28, 2024
Data Sourced
via Launchpad·05:46 PM
Description
Sep 17, 2024
Data Sourced
via Ubuntu·06:01 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31948?
CVE-2024-31948 has a severity rating that may lead to a denial of service by crashing the bgpd daemon.
2
How do I fix CVE-2024-31948?
To fix CVE-2024-31948, upgrade to the fixed versions of the FRRouting package, specifically 7.5.1-1.1+deb11u4 or 10.2.1-2.
3
Which software is affected by CVE-2024-31948?
CVE-2024-31948 affects the FRRouting (FRR) versions up to 9.1 on Debian systems.
4
What types of attacks can exploit CVE-2024-31948?
CVE-2024-31948 can be exploited through malformed Prefix SID attributes in BGP UPDATE packets.
5
What components are impacted by CVE-2024-31948?
The bgpd daemon in FRRouting is the component impacted by CVE-2024-31948, leading to potential crashes.