Debian Frr vulnerabilities
43 known vulnerabilities affecting debian/frr.
Total CVEs
43
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH26MEDIUM11LOW2
Vulnerabilities
Page 2 of 3
CVE-2025-61102P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61102 [HIGH] CVE-2025-61102: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer...
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.5.1-3)
sid: resolved (fixed in 10.5.1-3)
trixie: op
debian
CVE-2025-61101P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61101 [HIGH] CVE-2025-61101: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer...
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.5.1-3)
sid: resolved (fixed in 10.5.1-3)
trixi
debian
CVE-2025-61105P3HIGHCVSS 7.5fixed in frr 10.5.1-3 (forky)2025
CVE-2025-61105 [HIGH] CVE-2025-61105: frr - FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer...
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.5.1-3)
sid: resolved (fixed in 10.5.1-3)
trixie: open
debian
CVE-2023-3748P3LOWCVSS 3.5fixed in frr 9.1-0.1 (forky)2023
CVE-2023-3748 [LOW] CVE-2023-3748: frr - A flaw was found in FRRouting when parsing certain babeld unicast hello messages...
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
Scope: loca
debian
CVE-2022-26129P3HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26129 [HIGH] CVE-2022-26129: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1
debian
CVE-2023-31490P3HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-31490 [HIGH] CVE-2023-31490: frr - An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a den...
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved (fixed in 8.4.4-1)
debian
CVE-2022-26126P4HIGHCVSS 7.8fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-26126 [HIGH] CVE-2022-26126: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use ...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
debian
CVE-2023-41909P4HIGHCVSS 7.5fixed in frr 8.4.4-1 (bookworm)2023
CVE-2023-41909 [HIGH] CVE-2023-41909: frr - An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in...
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 8.4.4-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.4-1)
sid: resolved (fixed in 8.4.4-1)
trixie: resolved
debian
CVE-2024-34088P4HIGHCVSS 7.5fixed in frr 10.0.1-0.1 (forky)2024
CVE-2024-34088 [HIGH] CVE-2024-34088: frr - In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in os...
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.
debian
CVE-2023-47235P4HIGHCVSS 7.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-47235 [HIGH] CVE-2023-47235: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (
debian
CVE-2023-41358P4HIGHCVSS 7.5fixed in frr 8.4.4-1.1~deb12u1 (bookworm)2023
CVE-2023-41358 [HIGH] CVE-2023-41358: frr - An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processe...
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Scope: local
bookworm: resolved (fixed in 8.4.4-1.1~deb12u1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.4-1.1)
sid: resolved (fixed in 8.4.4-1.1)
trixie: resolved (fixed in 8.4.4-1.1)
debian
CVE-2022-43681P4MEDIUMCVSS 6.5fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-43681 [MEDIUM] CVE-2022-43681: frr - An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. Whe...
An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet, throwing a SIGABRT signal and exiting. This results in a bgpd daemon restart, causing a Den
debian
CVE-2024-31950P4MEDIUMCVSS 6.5fixed in frr 10.0.1-0.1 (forky)2024
CVE-2024-31950 [MEDIUM] CVE-2024-31950: frr - In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash ...
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
debian
CVE-2024-31948P4MEDIUMCVSS 6.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2024
CVE-2024-31948 [MEDIUM] CVE-2024-31948: frr - In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribu...
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
debian
CVE-2022-40318P4MEDIUMCVSS 6.5fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-40318 [MEDIUM] CVE-2022-40318: frr - An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BG...
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2)
debian
CVE-2022-40302P4MEDIUMCVSS 6.5fixed in frr 8.4.1-1 (bookworm)2022
CVE-2022-40302 [MEDIUM] CVE-2022-40302: frr - An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BG...
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2)
debian
CVE-2024-31949P4MEDIUMCVSS 6.5fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2024
CVE-2024-31949 [MEDIUM] CVE-2024-31949: frr - In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/G...
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10.0.1-0.1)
trixie: resolved (fixed in 10.0.1-0.1)
debian
CVE-2024-31951P4MEDIUMCVSS 6.5fixed in frr 10.0.1-0.1 (forky)2024
CVE-2024-31951 [MEDIUM] CVE-2024-31951: frr - In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can...
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 10.0.1-0.1)
sid: resolved (fixed in 10
debian
CVE-2023-46752P4MEDIUMCVSS 5.9fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-46752 [MEDIUM] CVE-2023-46752: frr - An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed ...
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian
CVE-2023-46753P4MEDIUMCVSS 5.9fixed in frr 7.5.1-1.1+deb11u3 (bullseye)2023
CVE-2023-46753 [MEDIUM] CVE-2023-46753: frr - An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a ...
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 9.1-0.1)
sid: resolved (fixed in 9.1-0.1)
trixie: resolved (fixed in 9.1-0.1)
debian