PT-2024-6034 · Frrouting+5 · Frrouting+5

Iggy Frankovic

·

Published

2024-04-07

·

Updated

2025-05-01

·

CVE-2024-31950

CVSS v2.0

6.6

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions through 9.1
Description The issue is related to a buffer overflow and daemon crash in the ospf te parse ri function for OSPF LSA packets during an attempt to read Segment Routing subTLVs, whose size is not validated. This can allow a remote attacker to cause a denial of service.
Recommendations For FRRouting versions through 9.1, as a temporary workaround, consider disabling the ospf te parse ri function until a patch is available. Restrict access to the OSPF LSA Packet Handler component to minimize the risk of exploitation. Avoid using the affected Segment Routing subTLVs in the OSPF LSA packets until the issue is resolved.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-39878
BDU:2024-06852
CVE-2024-31950
OPENSUSE-SU-2024:14038-1
OPENSUSE-SU-2024_1971-1
OPENSUSE-SU-2024_4090-1
SUSE-SU-2024:1971-1
SUSE-SU-2024:4090-1
SUSE-SU-2024_1971-1
USN-6794-1

Affected Products

Debian
Frrouting
Linuxmint
Red Os
Suse
Ubuntu