CVE-2024-31949
published 2024-04-07CVE-2024-31949: In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.70%
49.4th percentile
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 7.5.1-1.1+deb11u3 (bullseye) | frr 7.5.1-1.1+deb11u3 (bullseye) |
| frrouting | frrouting | <= 9.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-31949: In FRRouting (FRR) through 9
osv·2024-04-07·CVSS 6.5
CVE-2024-31949 [MEDIUM] CVE-2024-31949: In FRRouting (FRR) through 9
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
GHSA
GHSA-f3q5-vrp5-crqj: In FRRouting (FRR) through 9
ghsa_unreviewed·2024-04-07
CVE-2024-31949 [MEDIUM] CWE-835 GHSA-f3q5-vrp5-crqj: In FRRouting (FRR) through 9
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
Red Hat
frr: infinite loop
vendor_redhat·2024-04-07·CVSS 6.5
CVE-2024-31949 [MEDIUM] CWE-835 frr: infinite loop
frr: infinite loop
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
An infinite loop vulnerability was found in FRRouting. Malformed data when receiving an MP/GR capability as a dynamic capability can result in a pointer not advancing.
Statement: The infinite loop triggered by the receipt of a malformed MP/GR capability in FRRouting represents a moderate severity issue due to its potential impact on system stability and resource utilization. While it does not directly expose sensitive data or allow unauthorized access, the loop can lead to a Denial of Service (DoS) condition by consuming excessive CPU resources, thereby degrading the overall performance of the r
Debian
CVE-2024-31949: frr - In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/G...
vendor_debian·2024·CVSS 6.5
CVE-2024-31949 [MEDIUM] CVE-2024-31949: frr - In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/G...
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/FRRouting/frr/pull/15640https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219bhttps://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://github.com/FRRouting/frr/pull/15640https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219bhttps://lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
2024-04-07
Published