PT-2024-6034 · Frrouting+5 · Frrouting+5
Iggy Frankovic
·
Published
2024-04-07
·
Updated
2025-05-01
·
CVE-2024-31950
CVSS v2.0
6.6
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
FRRouting versions through 9.1
Description
The issue is related to a buffer overflow and daemon crash in the
ospf te parse ri function for OSPF LSA packets during an attempt to read Segment Routing subTLVs, whose size is not validated. This can allow a remote attacker to cause a denial of service.Recommendations
For FRRouting versions through 9.1, as a temporary workaround, consider disabling the
ospf te parse ri function until a patch is available. Restrict access to the OSPF LSA Packet Handler component to minimize the risk of exploitation. Avoid using the affected Segment Routing subTLVs in the OSPF LSA packets until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Frrouting
Linuxmint
Red Os
Suse
Ubuntu