CVE-2024-44070
published 2024-08-19CVE-2024-44070: An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.64%
46.6th percentile
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 7.5.1-1.1+deb11u3 (bullseye) | frr 7.5.1-1.1+deb11u3 (bullseye) |
| frrouting | frrouting | <= 10.1 | — |
| msrc | azl3_frr_9.1.1-2_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_frr_8.5.5-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_frr_8.5.5-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
frr vulnerabilities
osv·2025-01-27·CVSS 7.5
CVE-2024-44070 [HIGH] frr vulnerabilities
frr vulnerabilities
Iggy Frankovic discovered that FRR incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2024-44070)
It was discovered that FRR re-validated all routes in certain instances
when the internal socket's buffer size overflowed. A remote attacker could
possibly use this issue to impact the performance of FRR, resulting in a
denial of service. (CVE-2024-55553)
GHSA
GHSA-88xw-q94w-q9mr: An issue was discovered in FRRouting (FRR) through 10
ghsa_unreviewed·2024-08-19
CVE-2024-44070 [CRITICAL] GHSA-88xw-q94w-q9mr: An issue was discovered in FRRouting (FRR) through 10
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
OSV
CVE-2024-44070: An issue was discovered in FRRouting (FRR) through 10
osv·2024-08-19·CVSS 7.5
CVE-2024-44070 [HIGH] CVE-2024-44070: An issue was discovered in FRRouting (FRR) through 10
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2025-01-27·CVSS 7.5
CVE-2024-55553 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or exhibit degraded performance if it received
specially crafted network traffic.
Iggy Frankovic discovered that FRR incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2024-44070)
It was discovered that FRR re-validated all routes in certain instances
when the internal socket's buffer size overflowed. A remote attacker could
possibly use this issue to impact the performance of FRR, resulting in a
denial of service. (CVE-2024-55553)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Quagga vulnerability
vendor_ubuntu·2025-01-27
CVE-2024-44070 Quagga vulnerability
Title: Quagga vulnerability
Summary: Quagga could be made to crash if it received specially crafted network traffic.
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause Quagga
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Quagga vulnerability
vendor_ubuntu·2024-09-17
CVE-2024-44070 Quagga vulnerability
Title: Quagga vulnerability
Summary: Quagga could be made to crash if it received specially crafted network
traffic.
Iggy Frankovic discovered that Quagga incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause Quagga
to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FRR vulnerability
vendor_ubuntu·2024-09-17
CVE-2024-44070 FRR vulnerability
Title: FRR vulnerability
Summary: FRR could be made to crash if it received specially crafted network
traffic.
Iggy Frankovic discovered that FRR incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
frr: improper input validation in bgp_attr_encap() in bgpd/bgp_attr.c
vendor_redhat·2024-08-18·CVSS 7.5
CVE-2024-44070 [HIGH] CWE-20 frr: improper input validation in bgp_attr_encap() in bgpd/bgp_attr.c
frr: improper input validation in bgp_attr_encap() in bgpd/bgp_attr.c
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
A flaw was found in FRRouting (FRR). Improper input validation in the bgp_attr_encap function in the bgpd/bgp_attr.c file of the remaining stream length before assigning the TLV value can cause the bgpd daemon to crash, resulting in a denial of service.
Statement: Due to security checks performed by FRR, the abort function is called when this flaw is triggered, terminating the process immediately. Thus, this issue can only cause the bgpd daemon to crash, resulting in a denial of service with no other security impact.
Mitigation: Mitigation for this i
Microsoft
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
vendor_msrc·2024-08-13·CVSS 7.5
CVE-2024-44070 [HIGH] An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner:
Debian
CVE-2024-44070: frr - An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/...
vendor_debian·2024·CVSS 7.5
CVE-2024-44070 [HIGH] CVE-2024-44070: frr - An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/...
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 10.1-0.2)
sid: resolved (fixed in 10.1-0.2)
trixie: resolved (fixed in 10.1-0.2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-19
Published