USN-7230-2: FRR vulnerabilities
Iggy Frankovic discovered that FRR incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2024-44070) It was discovered that FRR re-validated all routes in certain instances when the internal socket's buffer size overflowed. A remote attacker could possibly use this issue to impact the performance of FRR, resulting in a denial of service. (CVE-2024-55553)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7230-2?
The severity of USN-7230-2 is marked as high due to its potential to cause denial of service.
How do I fix USN-7230-2?
To fix USN-7230-2, you should upgrade the FRR package to a version that has addressed the vulnerability.
Which versions of Ubuntu are affected by USN-7230-2?
USN-7230-2 affects Ubuntu 20.04, 22.04, 24.04, and 24.10.
What specific package is vulnerable in USN-7230-2?
The vulnerable package identified in USN-7230-2 is the FRR routing software.
Can USN-7230-2 be exploited remotely?
Yes, a remote attacker could exploit USN-7230-2 to cause the FRR service to crash.