Search CVE reports


Toggle filters

31 – 40 of 48 results


CVE-2023-41359

Medium priority
Not affected

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Ignored
quagga Not in release Not affected Not affected
Show less packages

CVE-2023-41358

Medium priority
Fixed

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Ignored
quagga Not in release Not in release Fixed Fixed
Show less packages

CVE-2023-38802

Medium priority
Fixed

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Not in release
quagga Not in release Not in release Not affected Not affected
Show less packages

CVE-2023-3748

Medium priority

Some fixes available 1 of 2

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Ignored
Show less packages

CVE-2023-31490

Medium priority
Fixed

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Not in release
Show less packages

CVE-2023-31489

Medium priority
Fixed

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages

CVE-2022-43681

Medium priority
Not affected

An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages

CVE-2022-40318

Medium priority
Not affected

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages

CVE-2022-40302

Medium priority
Not affected

An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages

CVE-2022-36440

Medium priority
Not affected

A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages