A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade frrNo solution exists | May 15, 2025 | Jul 24, 2023 |
| Suse | — | Upgrade libfrrfpm_pb0Upgrade libfrr_pb0Upgrade libfrrospfapiclient0Upgrade libfrrsnmp0Upgrade frr-develUpgrade frrUpgrade libfrrcares0Upgrade libmlag_pb0Upgrade libfrrzmq0Upgrade libfrr0 | Sep 21, 2023 | Jul 24, 2023 |
| Ubuntu | — | Upgrade frr | Jul 25, 2023 | Jul 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub