Debian Frr vulnerabilities
48 known vulnerabilities affecting debian/frr.
Total CVEs
48
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM11LOW7
Vulnerabilities
Page 2 of 3
CVE-2023-41361CRITICALCVSS 9.8fixed in frr 9.1-0.1 (forky)2023
CVE-2023-41361 [CRITICAL] CVE-2023-41361: frr - An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for...
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-47235HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-47235 [HIGH] CVE-2023-47235: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (
debian
CVE-2023-38802HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-38802 [HIGH] CVE-2023-38802: frr - FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker ...
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.4-1.1)
sid: resolved (fixed in 8.4.4-1.1)
tri
debian
CVE-2023-41358HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-41358 [HIGH] CVE-2023-41358: frr - An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processe...
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.4-1.1)
sid: resolved (fixed in 8.4.4-1.1)
trixie: resolved (fixed in 8.4.4-1.1)
debian
CVE-2023-38407HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-38407 [HIGH] CVE-2023-38407: frr - bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end o...
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-41909HIGHCVSS 7.5fixed in frr 8.4.4-1 (bookworm)2023
CVE-2023-41909 [HIGH] CVE-2023-41909: frr - An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in...
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 8.4.4-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved
debian
CVE-2023-47234HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-47234 [HIGH] CVE-2023-47234: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when p...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: res
debian
CVE-2023-31490HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-31490 [HIGH] CVE-2023-31490: frr - An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a den...
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved (fixed in 8.4.4-1)
debian
CVE-2023-31489MEDIUMCVSS 5.5fixed in frr 8.4.4-1 (bookworm)2023
CVE-2023-31489 [MEDIUM] CVE-2023-31489: frr - An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a den...
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
Scope: local
bookworm: resolved (fixed in 8.4.4-1)
bullseye: resolved
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved (fixed in 8.4.4-1)
debian
CVE-2023-46753MEDIUMCVSS 5.9fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-46753 [MEDIUM] CVE-2023-46753: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a ...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-46752MEDIUMCVSS 5.9fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-46752 [MEDIUM] CVE-2023-46752: frr - An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed ...
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-41359LOWCVSS 9.12023
CVE-2023-41359 [CRITICAL] CVE-2023-41359: frr - An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds ...
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2023-3748LOWCVSS 3.5fixed in frr 9.1-0.1 (forky)2023
CVE-2023-3748 [LOW] CVE-2023-3748: frr - A flaw was found in FRRouting when parsing certain babeld unicast hello messages...
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
Scope: loca
debian
CVE-2022-37032CRITICALCVSS 9.1fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-37032 [CRITICAL] CVE-2022-37032: frr - An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to ...
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u1)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolve
debian
CVE-2022-26127HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26127 [HIGH] CVE-2022-26127: frr - A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing...
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1
debian
CVE-2022-26129HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26129 [HIGH] CVE-2022-26129: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1
debian
CVE-2022-26128HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26128 [HIGH] CVE-2022-26128: frr - A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong...
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1
debian
CVE-2022-26126HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26126 [HIGH] CVE-2022-26126: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use ...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
debian
CVE-2022-26125HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26125 [HIGH] CVE-2022-26125: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
debian
CVE-2022-36440HIGHCVSS 7.5fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-36440 [HIGH] CVE-2022-36440: frr - A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_...
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed
debian