CVE-2024-27913
published 2024-02-28CVE-2024-27913: ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed…
PriorityP424medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.32%
24.3th percentile
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 9.1-0.1 (forky) | frr 9.1-0.1 (forky) |
| frrouting | frrouting | < 9.0 | 9.0 |
| msrc | cbl2_frr_8.5.3-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_frr_8.5.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-27913: ospf_te_parse_te in ospfd/ospf_te
osv·2024-02-28·CVSS 6.5
CVE-2024-27913 [MEDIUM] CVE-2024-27913: ospf_te_parse_te in ospfd/ospf_te
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
GHSA
GHSA-46v4-9j9w-fv79: ospf_te_parse_te in ospfd/ospf_te
ghsa_unreviewed·2024-02-28
CVE-2024-27913 [MEDIUM] CWE-909 GHSA-46v4-9j9w-fv79: ospf_te_parse_te in ospfd/ospf_te
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
Ubuntu
FRR vulnerability
vendor_ubuntu·2024-03-06
CVE-2024-27913 FRR vulnerability
Title: FRR vulnerability
Summary: FRR could be made to crash if it received specially crafted network
traffic.
It was discovered that FRR incorrectly handled certain malformed OSPF LSA
packets. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
frr: Denial of service via malformed OSPF LSA packet
vendor_redhat·2024-02-28·CVSS 6.5
CVE-2024-27913 [MEDIUM] CWE-703 frr: Denial of service via malformed OSPF LSA packet
frr: Denial of service via malformed OSPF LSA packet
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
A flaw was found in FRRouting. A missing check for a NULL attribute in the ospf_te_parse_te in ospfd/ospf_te.c file may lead to a crash of the ospfd daemon and a denial of service through a malformed OSPF LSA packet.
Statement: This vulnerability in FRRouting (FRR), specifically within the ospf_te_parse_te function, poses a moderate severity risk due to its potential to cause a denial-of-service (DoS) condition in the ospfd daemon. The issue arises from improper handling of malformed OSPF Link State Adve
Microsoft
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet because of an attempted acc
vendor_msrc·2024-02-13·CVSS 6.5
CVE-2024-27913 [MEDIUM] ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet because of an attempted acc
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet because of an attempted access to a missing attribute field.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products
Debian
CVE-2024-27913: frr - ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote...
vendor_debian·2024·CVSS 6.5
CVE-2024-27913 [MEDIUM] CVE-2024-27913: frr - ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote...
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-28
Published