USN-7016-1: FRR vulnerability
Published Sep 17, 2024
·Updated
Iggy Frankovic discovered that FRR incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/frr<8.4.4-1.1ubuntu6.2
8.4.4-1.1ubuntu6.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/frr<8.1-1ubuntu1.11
8.1-1ubuntu1.11
Ubuntu Ubuntu=22.04
Event History
Sep 17, 2024
Advisory Published
via Ubuntu·12:00 AM
Data Sourced
via Ubuntu·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of USN-7016-1?
The severity of USN-7016-1 is classified as a denial of service vulnerability.
2
How do I fix USN-7016-1?
To fix USN-7016-1, update the FRR package to version 8.4.4-1.1ubuntu6.2 or 8.1-1ubuntu1.11 depending on your Ubuntu version.
3
Which versions of Ubuntu are affected by USN-7016-1?
Ubuntu versions 24.04 and 22.04 are affected by USN-7016-1 if they are running vulnerable FRR versions.
4
What is the main impact of USN-7016-1?
The main impact of USN-7016-1 is that a remote attacker may exploit the vulnerability to cause the FRR service to crash.
5
Who discovered the issue described in USN-7016-1?
The issue described in USN-7016-1 was discovered by Iggy Frankovic.