In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade frr | May 15, 2025 | Apr 30, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 30, 2024 |
| Suse | — | Upgrade frrUpgrade libmlag_pb0Upgrade libfrr_pb0Upgrade frr-develUpgrade libfrrcares0Upgrade libfrrzmq0Upgrade libfrr0Upgrade libfrrsnmp0Upgrade libfrrospfapiclient0Upgrade libmgmt_be_nb0Upgrade libfrrfpm_pb0 | Jun 12, 2024 | Apr 30, 2024 |
| Ubuntu | — | Upgrade frr | Jun 6, 2024 | Apr 30, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Apr 30, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub