INFCSA-2024:2156: frr security update

Information about definition

Identificator: INFCSA-2024:2156

Type: security

Release date: 2025-09-24 19:26:12 UTC

Information about package

FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.

Vulnerabilities description

  • CVE-2023-31489

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.

  • CVE-2023-31490

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

  • CVE-2023-41358

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

  • CVE-2023-41359

    An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

  • CVE-2023-41360

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

  • CVE-2023-41909

    An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.

  • CVE-2023-46752

    An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.

  • CVE-2023-46753

    An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 5.5 no information
no information 7.5 no information
no information 7.5 no information
no information 5.9 no information
no information 4.8 no information
no information 7.5 no information
no information 5.9 no information
no information 5.9 no information
Critical, important, moderate, low

Updated packages

loader icon Preparing to download...
Architecture: Download