CVE-2023-47234
published 2023-11-03CVE-2023-47234: An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.91%
55.8th percentile
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 7.5.1-1.1+deb11u3 (bullseye) | frr 7.5.1-1.1+deb11u3 (bullseye) |
| frrouting | frrouting | <= 9.0.1 | — |
| msrc | azl3_frr_8.5.3-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_frr_9.1-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_frr_8.5.3-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-10-29·CVSS 9.8
CVE-2019-17006 [CRITICAL] PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0012 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2019-17006 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-3518 This CVE is fixed in PAN-OS 10.2.0, and all later versions of PAN-OS. CVE-2021-25219 This CVE is fixed in PAN-OS 10.2.3, and all later versions of PAN-OS. CVE-2021-27645 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions of PAN-OS. CVE-2021-34798 This CVE is fixed in PAN-OS 10.2.8, PAN-OS 11.0.2, and all later versions o
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2023-11-21
CVE-2023-38407 FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain BGP messages. A
remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory p
vendor_msrc·2023-11-14·CVSS 7.5
CVE-2023-47234 [HIGH] An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory p
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we
Red Hat
frr: crash from specially crafted MP_UNREACH_NLRI-containing BGP UPDATE message
vendor_redhat·2023-11-03·CVSS 7.5
CVE-2023-47234 [HIGH] frr: crash from specially crafted MP_UNREACH_NLRI-containing BGP UPDATE message
frr: crash from specially crafted MP_UNREACH_NLRI-containing BGP UPDATE message
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
A flaw was found in frr. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data that lacks mandatory path attributes.
Statement: Red Hat OpenStack Platform does not ship its own version of the frr package, instead using the version from the underlying Red Hat Enterprise Linux. RHOSP is marked as Not Affected as no changes need to be made by the OpenStack engineering team. System administrators of OpenStack deployments should apply
Debian
CVE-2023-47234: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when p...
vendor_debian·2023·CVSS 7.5
CVE-2023-47234 [HIGH] CVE-2023-47234: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when p...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
GHSA
GHSA-v9pv-vrqw-885r: An issue was discovered in FRRouting FRR through 9
ghsa_unreviewed·2023-11-03
CVE-2023-47234 [HIGH] GHSA-v9pv-vrqw-885r: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
OSV
CVE-2023-47234: An issue was discovered in FRRouting FRR through 9
osv·2023-11-03·CVSS 7.5
CVE-2023-47234 [HIGH] CVE-2023-47234: An issue was discovered in FRRouting FRR through 9
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bfhttps://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bfhttps://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
2023-11-03
Published