CVE-2023-38406
published 2023-11-06CVE-2023-38406: bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.94%
56.9th percentile
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 8.4.4-1.1~deb12u1 (bookworm) | frr 8.4.4-1.1~deb12u1 (bookworm) |
| frrouting | frrouting | < 8.4.3 | 8.4.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2023-11-21
CVE-2023-38407 FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain BGP messages. A
remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ffr: Flowspec overflow in bgpd/bgp_flowspec.c
vendor_redhat·2023-02-24·CVSS 9.8
CVE-2023-38406 [CRITICAL] CWE-119 ffr: Flowspec overflow in bgpd/bgp_flowspec.c
ffr: Flowspec overflow in bgpd/bgp_flowspec.c
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
A flaw was found in bgpd/bgp_flowspec.c in the FFrouting BGP protocol code. An overflow may occur while processing zero length NLRI messages.
Statement: Red Hat OpenStack Platform does not ship its own version of the frr package, instead using the version from the underlying Red Hat Enterprise Linux. RHOSP is marked as Not Affected as no changes need to be made by the OpenStack engineering team. System administrators of OpenStack deployments should apply updates once available in RHEL.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteri
Debian
CVE-2023-38406: frr - bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of...
vendor_debian·2023·CVSS 9.8
CVE-2023-38406 [CRITICAL] CVE-2023-38406: frr - bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of...
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved (fixed in 8.4.4-1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
GHSA
GHSA-8jp5-89m5-6xp3: bgpd/bgp_flowspec
ghsa_unreviewed·2023-11-06
CVE-2023-38406 [CRITICAL] CWE-755 GHSA-8jp5-89m5-6xp3: bgpd/bgp_flowspec
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
OSV
CVE-2023-38406: bgpd/bgp_flowspec
osv·2023-11-06·CVSS 9.8
CVE-2023-38406 [CRITICAL] CVE-2023-38406: bgpd/bgp_flowspec
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FRRouting/frr/compare/frr-8.4.2...frr-8.4.3https://github.com/FRRouting/frr/pull/12884https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://github.com/FRRouting/frr/compare/frr-8.4.2...frr-8.4.3https://github.com/FRRouting/frr/pull/12884https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
2023-11-06
Published