CVE-2023-3748Infinite Loop in Frrouting

CWE-835Infinite Loop6 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.1%
top 78.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 24

Description

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/frr< frr 9.1-0.1 (forky)

🔴Vulnerability Details

2
OSV
CVE-2023-3748: A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored2023-07-24
GHSA
GHSA-w8cg-4xhg-9fgw: A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored2023-07-24

📋Vendor Advisories

3
Ubuntu
FRR vulnerability2023-07-24
Red Hat
frr: Inifinite loop in babld message parsing may cause DoS2023-04-15
Debian
CVE-2023-3748: frr - A flaw was found in FRRouting when parsing certain babeld unicast hello messages...2023