USN-6481-1: FRR vulnerabilities
It was discovered that FRR incorrectly handled certain malformed NLRI data. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2023-46752) It was discovered that FRR incorrectly handled certain BGP UPDATE messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2023-46753)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6481-1?
The severity of USN-6481-1 is rated as a denial of service vulnerability that allows a remote attacker to crash the FRR application.
How do I fix USN-6481-1?
To fix USN-6481-1, update the FRR package to the recommended versions 8.4.4-1.1ubuntu1.1, 8.4.2-1ubuntu1.5, or 8.1-1ubuntu1.7 depending on your Ubuntu version.
Which versions of FRR are affected by USN-6481-1?
Versions of FRR 8.1 up to 8.1-1ubuntu1.7, 8.4.2 up to 8.4.2-1ubuntu1.5, and 8.4.4 up to 8.4.4-1.1ubuntu1.1 are affected by USN-6481-1.
What component of FRR is impacted by USN-6481-1?
USN-6481-1 impacts the handling of malformed NLRI data and BGP UPDATE messages within the FRR application.
Can USN-6481-1 lead to data loss?
While USN-6481-1 primarily causes a denial of service, it may indirectly result in data loss by making the networking services unavailable.