PT-2023-9203 · Frrouting+8 · Frrouting+8
Iggy Frankovic
·
Published
2023-02-24
·
Updated
2024-11-28
·
CVE-2023-38406
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FRRouting versions prior to 8.4.3
Description
The issue is related to the handling of incorrect requests without attributes in the bgpd/bgp flowspec.c file of FRRouting, a Unix-like system network routing implementation tool. This can be exploited by a remote attacker to cause a denial of service, due to a "flowspec overflow" when an nlri length of zero is mishandled.
Recommendations
For versions prior to 8.4.3, update to version 8.4.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the bgpd/bgp flowspec.c module to minimize the risk of exploitation.
Fix
DoS
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Centos
Frrouting
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu