cbcvebase.

Debian Frr vulnerabilities

43 known vulnerabilities affecting debian/frr.

Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM11LOW2

Vulnerabilities

Page 1 of 3
CVE-2022-37035P3HIGHCVSS 8.1fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-37035 [HIGH] CVE-2022-37035: frr - An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_... An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation. Scope: local bookworm: resolved (fi
debian
CVE-2023-38406P3CRITICALCVSS 9.8fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-38406 [CRITICAL] CVE-2023-38406: frr - bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of... bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow." Scope: local bookworm: resolved (fixed in 8.4.4-1.1~deb12u1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 8.4.4-1) sid: resolved (fixed in 8.4.4-1) trixie: resolved (fixed in 8.4.4-1)
debian
CVE-2023-41361P3CRITICALCVSS 9.8fixed in frr 9.1-0.1 (forky)2023
CVE-2023-41361 [CRITICAL] CVE-2023-41361: frr - An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for... An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version. Scope: local bookworm: open bullseye: resolved forky: resolved (fixed in 9.1-0.1) sid: resolved (fixed in 9.1-0.1) trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2022-37032P3CRITICALCVSS 9.1fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-37032 [CRITICAL] CVE-2022-37032: frr - An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to ... An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. Scope: local bookworm: resolved (fixed in 8.4.1-1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u1) forky: resolved (fixed in 8.4.1-1) sid: resolved (fixed in 8.4.1-1) trixie: resolve
debian
CVE-2024-55553P3HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u4 (bullseye)2024
CVE-2024-55553 [HIGH] CVE-2024-55553: frr - In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if t... In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An attacker can use this to trigger re-parsing of the RIB for FRR routers using RTR by causing more than this number of updates during an update interval (usually 30 minutes). Addi
debian
CVE-2023-41360P3CRITICALCVSS 9.1fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-41360 [CRITICAL] CVE-2023-41360: frr - An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read... An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation. Scope: local bookworm: resolved (fixed in 8.4.4-1.1~deb12u1) bullseye: resolved forky: resolved (fixed in 8.4.4-1.1) sid: resolved (fixed in 8.4.4-1.1) trixie: resolved (fixed in 8.4.4-1.1)
debian
CVE-2022-36440P3HIGHCVSS 7.5fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-36440 [HIGH] CVE-2022-36440: frr - A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_... A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS. Scope: local bookworm: resolved (fixed in 8.4.1-1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u2) forky: resolved (fixed in 8.4.1-1) sid: resolved (fixed
debian
CVE-2022-26125P3HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26125 [HIGH] CVE-2022-26125: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch... Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c. Scope: local bookworm: resolved (fixed in 8.4.1-1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 8.4.1-1) sid: resolved (fixed in 8.4.1-1) trixie: resolved (fixed in 8.4.1-1)
debian
CVE-2024-44070P3HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2024
CVE-2024-44070 [HIGH] CVE-2024-44070: frr - An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/... An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value. Scope: local bookworm: open bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 10.1-0.2) sid: resolved (fixed in 10.1-0.2) trixie: resolved (fixed in 10.1-0.2)
debian
CVE-2025-61107P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61107 [HIGH] CVE-2025-61107: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3) tri
debian
CVE-2025-61106P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61106 [HIGH] CVE-2025-61106: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3) trixie: o
debian
CVE-2025-61103P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61103 [HIGH] CVE-2025-61103: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3) trixie
debian
CVE-2025-61104P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61104 [HIGH] CVE-2025-61104: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3) trixie: open
debian
CVE-2025-61100P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61100 [HIGH] CVE-2025-61100: frr - FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3
debian
CVE-2025-61099P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61099 [HIGH] CVE-2025-61099: frr - FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer... FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 10.5.1-3) sid: resolved (fixed in 10.5.1-3) trixie: o
debian
CVE-2022-26127P3HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26127 [HIGH] CVE-2022-26127: frr - A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing... A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c. Scope: local bookworm: resolved (fixed in 8.4.1-1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 8.4.1-1) sid: resolved (fixed in 8.4.1-1) trixie: resolved (fixed in 8.4.1
debian
CVE-2022-26128P3HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26128 [HIGH] CVE-2022-26128: frr - A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong... A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c. Scope: local bookworm: resolved (fixed in 8.4.1-1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 8.4.1-1) sid: resolved (fixed in 8.4.1-1) trixie: resolved (fixed in 8.4.1-1
debian
CVE-2023-38802P3HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-38802 [HIGH] CVE-2023-38802: frr - FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker ... FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation). Scope: local bookworm: resolved (fixed in 8.4.4-1.1~deb12u1) bullseye: resolved (fixed in 7.5.1-1.1+deb11u2) forky: resolved (fixed in 8.4.4-1.1) sid: resolved (fixed in 8.4.4-1.1) tri
debian
CVE-2023-38407P3HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-38407 [HIGH] CVE-2023-38407: frr - bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end o... bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing. Scope: local bookworm: open bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 9.1-0.1) sid: resolved (fixed in 9.1-0.1) trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-47234P3HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-47234 [HIGH] CVE-2023-47234: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when p... An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes). Scope: local bookworm: open bullseye: resolved (fixed in 7.5.1-1.1+deb11u3) forky: resolved (fixed in 9.1-0.1) sid: resolved (fixed in 9.1-0.1) trixie: res
debian