CVE-2024-31950
published 2024-04-07CVE-2024-31950: In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.51%
40.4th percentile
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 10.0.1-0.1 (forky) | frr 10.0.1-0.1 (forky) |
| frrouting | frrouting | <= 9.1 | — |
| msrc | cbl2_frr_8.5.3-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_frr_8.5.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-05-28
CVE-2024-31950 FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain malformed BGP and
OSPF packets. A remote attacker could use this issue to cause FRR to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
In FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
vendor_msrc·2024-04-09·CVSS 6.5
CVE-2024-31950 [MEDIUM] CWE-120 In FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
In FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the
Red Hat
frr: buffer overflow and daemon crash in ospf_te_parse_ri
vendor_redhat·2024-04-07·CVSS 6.5
CVE-2024-31950 [MEDIUM] CWE-121 frr: buffer overflow and daemon crash in ospf_te_parse_ri
frr: buffer overflow and daemon crash in ospf_te_parse_ri
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
A buffer overflow vulnerability was found in FRRouting. There can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs.
Statement: The buffer overflow vulnerability in FRRouting's ospf_te_parse_ri function, specifically when processing OSPF LSA packets containing Segment Routing subTLVs, is classified as a moderate severity issue. While buffer overflows can potentially lead to arbitrary code execution or daemon crashes, this particular vulnerability require
Debian
CVE-2024-31950: frr - In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash ...
vendor_debian·2024·CVSS 6.5
CVE-2024-31950 [MEDIUM] CVE-2024-31950: frr - In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash ...
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
OSV
CVE-2024-31950: In FRRouting (FRR) through 9
osv·2024-04-07·CVSS 6.5
CVE-2024-31950 [MEDIUM] CVE-2024-31950: In FRRouting (FRR) through 9
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
GHSA
GHSA-36p4-cjjg-rccj: In FRRouting (FRR) through 9
ghsa_unreviewed·2024-04-07
CVE-2024-31950 [MEDIUM] CWE-120 GHSA-36p4-cjjg-rccj: In FRRouting (FRR) through 9
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-07
Published