A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 3.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution existsUpgrade frr | May 15, 2025 | Jul 24, 2023 |
| Suse | — | Upgrade libfrr0Upgrade libmlag_pb0Upgrade frr-develUpgrade libfrrzmq0Upgrade libfrrcares0Upgrade frrUpgrade libfrrsnmp0Upgrade libfrrfpm_pb0Upgrade libfrr_pb0Upgrade libfrrospfapiclient0 | Sep 21, 2023 | Jul 24, 2023 |
| Ubuntu | — | Upgrade frr | Jul 25, 2023 | Jul 24, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub