PT-2024-6035 · Frrouting+6 · Frrouting+6

Published

2024-04-07

·

Updated

2024-12-09

·

CVE-2024-34088

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FRRouting versions through 9.1
Description The issue is related to the get edge() function in the ospf te.c file of the OSPF daemon component in FRRouting, which can return a NULL pointer. If calling functions do not handle this NULL value, the OSPF daemon may crash, leading to a denial of service. This can be exploited by a remote attacker to cause service disruption.
Recommendations For FRRouting versions through 9.1, consider disabling the get edge() function as a temporary workaround until a patch is available. Restrict access to the OSPF daemon to minimize the risk of exploitation. Update to a version later than 9.1 when available.

Fix

DoS

NULL Pointer Dereference

Improper Resource Release

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16579
AZL-40261
BDU:2024-06853
CVE-2024-34088
OPENSUSE-SU-2024:14038-1
OPENSUSE-SU-2024_1971-1
OPENSUSE-SU-2024_4090-1
SUSE-SU-2024:1971-1
SUSE-SU-2024:4090-1
USN-6794-1

Affected Products

Alt Linux
Debian
Frrouting
Linuxmint
Red Os
Suse
Ubuntu