CVE-2024-31951
published 2024-04-07CVE-2024-31951: In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA…
PriorityP426medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.54%
42.2th percentile
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 10.0.1-0.1 (forky) | frr 10.0.1-0.1 (forky) |
| frrouting | frrouting | <= 9.1 | — |
| msrc | cbl2_frr_8.5.3-6_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_frr_8.5.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-05-28
CVE-2024-31950 FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain malformed BGP and
OSPF packets. A remote attacker could use this issue to cause FRR to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment R
vendor_msrc·2024-04-09·CVSS 6.5
CVE-2024-31951 [MEDIUM] CWE-120 In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment R
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1 there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact
Red Hat
frr: buffer overflow in ospf_te_parse_ext_link
vendor_redhat·2024-04-07·CVSS 6.5
CVE-2024-31951 [MEDIUM] CWE-121 frr: buffer overflow in ospf_te_parse_ext_link
frr: buffer overflow in ospf_te_parse_ext_link
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
A buffer overflow vulnerability was found in FRRouting. There can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs.
Statement: The vulnerability in the Opaque LSA Extended Link parser in FRRouting (FRR), which allows for a buffer overflow and potential daemon crash when processing OSPF LSA packets with improperly validated Segment Routing Adjacency SID subTLVs, is classified as a moderate
Debian
CVE-2024-31951: frr - In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can...
vendor_debian·2024·CVSS 6.5
CVE-2024-31951 [MEDIUM] CVE-2024-31951: frr - In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can...
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
GHSA
GHSA-h4c3-x7vv-8q28: In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9
ghsa_unreviewed·2024-04-07
CVE-2024-31951 [MEDIUM] CWE-120 GHSA-h4c3-x7vv-8q28: In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
OSV
CVE-2024-31951: In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9
osv·2024-04-07·CVSS 6.5
CVE-2024-31951 [MEDIUM] CVE-2024-31951: In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-07
Published