vulnerability

Red Hat: CVE-2023-38802: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Aug 29, 2023
Added
Sep 19, 2023
Modified
Mar 27, 2026

Description

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

Solutions

redhat-upgrade-frrredhat-upgrade-frr-debuginforedhat-upgrade-frr-debugsourceredhat-upgrade-frr-selinux
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.