CVE-2023-38407
published 2023-11-06CVE-2023-38407: bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.93%
56.5th percentile
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 7.5.1-1.1+deb11u3 (bullseye) | frr 7.5.1-1.1+deb11u3 (bullseye) |
| frrouting | frrouting | < 8.5 | 8.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2023-11-21
CVE-2023-38407 FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain BGP messages. A
remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ffr: Out of bounds read in bgpd/bgp_label.c
vendor_redhat·2023-03-05·CVSS 7.5
CVE-2023-38407 [HIGH] CWE-125 ffr: Out of bounds read in bgpd/bgp_label.c
ffr: Out of bounds read in bgpd/bgp_label.c
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
An out-of-bounds read flaw was found in FFrounting beyond the end of the stream during labeled unicast parsing. This issue may lead to application crash and denial of service.
Statement: Red Hat OpenStack Platform does not ship its own version of the frr package, instead using the version from the underlying Red Hat Enterprise Linux. RHOSP is marked as Not Affected as no changes need to be made by the OpenStack engineering team. System administrators of OpenStack deployments should apply updates once available in RHEL.
Mitigation: Mitigation for this issue is either not available or the currently available options do no
Debian
CVE-2023-38407: frr - bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end o...
vendor_debian·2023·CVSS 7.5
CVE-2023-38407 [HIGH] CVE-2023-38407: frr - bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end o...
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
GHSA
GHSA-38fw-5cvw-p8h6: bgpd/bgp_label
ghsa_unreviewed·2023-11-06
CVE-2023-38407 [HIGH] GHSA-38fw-5cvw-p8h6: bgpd/bgp_label
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
OSV
CVE-2023-38407: bgpd/bgp_label
osv·2023-11-06·CVSS 7.5
CVE-2023-38407 [HIGH] CVE-2023-38407: bgpd/bgp_label
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FRRouting/frr/compare/frr-8.5-rc...frr-8.5https://github.com/FRRouting/frr/pull/12951https://github.com/FRRouting/frr/pull/12956https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://github.com/FRRouting/frr/compare/frr-8.5-rc...frr-8.5https://github.com/FRRouting/frr/pull/12951https://github.com/FRRouting/frr/pull/12956https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
2023-11-06
Published