An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade frrUpgrade frr-selinux | May 8, 2024 | Oct 26, 2023 |
| Debian | — | Upgrade frr | Apr 29, 2024 | Oct 26, 2023 |
| Oracle_linux | — | Upgrade frr-selinuxUpgrade frr | May 15, 2024 | Oct 26, 2023 |
| Redhat_linux | — | Upgrade frr-debugsourceUpgrade frrUpgrade frr-selinuxUpgrade frr-debuginfo | May 1, 2024 | Oct 26, 2023 |
| Rocky_linux | — | Upgrade frr-debuginfoUpgrade frrUpgrade frr-debugsource | May 8, 2025 | Oct 26, 2023 |
| Suse | — | Upgrade libfrrzmq0Upgrade libfrrcares0Upgrade libfrrgrpc_pb0Upgrade libfrrfpm_pb0Upgrade libfrrsnmp0Upgrade libfrrospfapiclient0Upgrade libmlag_pb0Upgrade frrUpgrade libfrr0Upgrade libfrr_pb0Upgrade frr-devel | Nov 20, 2023 | Oct 26, 2023 |
| Ubuntu | — | Upgrade frrUpgrade frr (Ubuntu Pro) | Nov 16, 2023 | Oct 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub