PT-2023-9203 · Frrouting+8 · Frrouting+8

·

CVE-2023-38406

·

Published

2023-02-24

·

Updated

2024-11-28

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions prior to 8.4.3
Description The issue is related to the handling of incorrect requests without attributes in the bgpd/bgp flowspec.c file of FRRouting, a Unix-like system network routing implementation tool. This can be exploited by a remote attacker to cause a denial of service, due to a "flowspec overflow" when an nlri length of zero is mishandled.
Recommendations For versions prior to 8.4.3, update to version 8.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the bgpd/bgp flowspec.c module to minimize the risk of exploitation.

Exploit

Fix

DoS

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:0130
ALSA-2024:0477
BDU:2024-04613
CESA-2024_0130
CVE-2023-38406
DLA-3797-1
DLA-3865-1
OPENSUSE-SU-2024:13487-1
OPENSUSE-SU-2024_2245-1
OPENSUSE-SU-2024_4090-1
RHSA-2024:0130
RHSA-2024:0477
RHSA-2024:0574
RHSA-2024:1093
RHSA-2024:1113
RHSA-2024:1152
RHSA-2024_0130
RHSA-2024_0477
RLSA-2024:0130
SUSE-SU-2023:4663-1
SUSE-SU-2023_4663-1
SUSE-SU-2024:2245-1
SUSE-SU-2024:4090-1
SUSE-SU-2024_2245-1
USN-6498-1
USN-6807-1

Affected Products

Almalinux
Centos
Frrouting
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu