CVE-2023-46752Uncontrolled Resource Consumption in Frrouting

Severity
5.9MEDIUMNVD
OSV7.8
EPSS
0.1%
top 65.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 26
Latest updateJun 5

Description

An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages9 packages

debiandebian/frr< frr 7.5.1-1.1+deb11u3 (bullseye)

Patches

🔴Vulnerability Details

4
OSV
frr vulnerabilities2024-06-05
OSV
frr vulnerabilities2023-11-15
OSV
CVE-2023-46752: An issue was discovered in FRRouting FRR through 92023-10-26
GHSA
GHSA-v7w5-g2hv-9797: An issue was discovered in FRRouting FRR through 92023-10-26

📋Vendor Advisories

5
Ubuntu
FRR vulnerabilities2024-06-05
Ubuntu
FRR vulnerabilities2023-11-15
Red Hat
frr: mishandled malformed data leading to a crash2023-10-26
Microsoft
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data leading to a crash.2023-10-10
Debian
CVE-2023-46752: frr - An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed ...2023