PT-2023-9203 · Frrouting+8 · Frrouting+8

Iggy Frankovic

·

Published

2023-02-24

·

Updated

2024-11-28

·

CVE-2023-38406

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions prior to 8.4.3
Description The issue is related to the handling of incorrect requests without attributes in the bgpd/bgp flowspec.c file of FRRouting, a Unix-like system network routing implementation tool. This can be exploited by a remote attacker to cause a denial of service, due to a "flowspec overflow" when an nlri length of zero is mishandled.
Recommendations For versions prior to 8.4.3, update to version 8.4.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the bgpd/bgp flowspec.c module to minimize the risk of exploitation.

Fix

DoS

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

ALSA-2024:0130
ALSA-2024:0477
BDU:2024-04613
CESA-2024_0130
CVE-2023-38406
DLA-3797-1
DLA-3865-1
OPENSUSE-SU-2024:13487-1
OPENSUSE-SU-2024_2245-1
OPENSUSE-SU-2024_4090-1
RHSA-2024:0130
RHSA-2024:0477
RHSA-2024:0574
RHSA-2024:1093
RHSA-2024:1113
RHSA-2024:1152
RHSA-2024_0130
RHSA-2024_0477
RLSA-2024:0130
SUSE-SU-2023:4663-1
SUSE-SU-2023_4663-1
SUSE-SU-2024:2245-1
SUSE-SU-2024:4090-1
SUSE-SU-2024_2245-1
USN-6498-1
USN-6807-1

Affected Products

Almalinux
Centos
Frrouting
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu