CVE-2024-31948
- EPSS 0.08%
- Veröffentlicht 07.04.2024 21:15:07
- Zuletzt bearbeitet 04.11.2025 17:15:51
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
CVE-2024-27913
- EPSS 0.08%
- Veröffentlicht 28.02.2024 07:15:09
- Zuletzt bearbeitet 26.03.2025 21:15:21
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
CVE-2023-38407
- EPSS 0.21%
- Veröffentlicht 06.11.2023 06:15:40
- Zuletzt bearbeitet 04.11.2025 17:15:37
bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.
CVE-2023-38406
- EPSS 0.11%
- Veröffentlicht 06.11.2023 06:15:40
- Zuletzt bearbeitet 04.11.2025 17:15:37
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
CVE-2023-47235
- EPSS 0.14%
- Veröffentlicht 03.11.2023 21:15:17
- Zuletzt bearbeitet 04.11.2025 17:15:38
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
CVE-2023-47234
- EPSS 0.19%
- Veröffentlicht 03.11.2023 21:15:17
- Zuletzt bearbeitet 04.11.2025 17:15:38
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
CVE-2023-46753
- EPSS 0.13%
- Veröffentlicht 26.10.2023 05:15:26
- Zuletzt bearbeitet 04.11.2025 17:15:38
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
CVE-2023-46752
- EPSS 0.14%
- Veröffentlicht 26.10.2023 05:15:26
- Zuletzt bearbeitet 04.11.2025 17:15:38
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVE-2023-41909
- EPSS 0.1%
- Veröffentlicht 05.09.2023 07:15:14
- Zuletzt bearbeitet 21.11.2024 08:21:53
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
CVE-2023-38802
- EPSS 0.94%
- Veröffentlicht 29.08.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:13
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).