CVE-2023-46753
published 2023-10-26CVE-2023-46753: An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an…
PriorityP425medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.78%
52.3th percentile
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 7.5.1-1.1+deb11u3 (bullseye) | frr 7.5.1-1.1+deb11u3 (bullseye) |
| frrouting | frrouting | <= 9.0.1 | — |
| msrc | azl3_frr_8.5.3-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_frr_9.1-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_frr_8.5.3-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Ubuntu
Quagga vulnerabilities
vendor_ubuntu·2023-11-15
CVE-2022-37032 Quagga vulnerabilities
Title: Quagga vulnerabilities
Summary: Quagga could be made to crash if it received specially crafted network
traffic.
It was discovered that Quagga incorrectly handled certain BGP messages. A
remote attacker could possibly use this issue to cause Quagga to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2023-11-15·CVSS 5.9
CVE-2023-46752 [MEDIUM] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash if it received specially crafted network
traffic.
It was discovered that FRR incorrectly handled certain malformed NLRI data.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2023-46752)
It was discovered that FRR incorrectly handled certain BGP UPDATE messages.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2023-46753)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
frr: crafted BGP UPDATE message leading to a crash
vendor_redhat·2023-10-26·CVSS 5.9
CVE-2023-46753 [MEDIUM] CWE-400 frr: crafted BGP UPDATE message leading to a crash
frr: crafted BGP UPDATE message leading to a crash
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
A flaw was found in FRRouting. A crash can occur for a crafted BGP UPDATE message without mandatory attributes (for example, one with only an unknown transit attribute).
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Microsoft
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.
vendor_msrc·2023-10-10·CVSS 5.9
CVE-2023-46753 [MEDIUM] CWE-863 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect
Debian
CVE-2023-46753: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a ...
vendor_debian·2023·CVSS 5.9
CVE-2023-46753 [MEDIUM] CVE-2023-46753: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a ...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
OSV
frr vulnerabilities
osv·2023-11-15·CVSS 5.9
CVE-2023-46752 [MEDIUM] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain malformed NLRI data.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2023-46752)
It was discovered that FRR incorrectly handled certain BGP UPDATE messages.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2023-46753)
OSV
CVE-2023-46753: An issue was discovered in FRRouting FRR through 9
osv·2023-10-26·CVSS 5.9
CVE-2023-46753 [MEDIUM] CVE-2023-46753: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
GHSA
GHSA-33fq-cj88-4v27: An issue was discovered in FRRouting FRR through 9
ghsa_unreviewed·2023-10-26
CVE-2023-46753 [HIGH] CWE-863 GHSA-33fq-cj88-4v27: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
No detection rules found.
No public exploits indexed.
https://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9https://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
2023-10-26
Published