← Back to CVE Index

CVE-2023-3748

Disclosed 2023-07-24

Description

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

Severity & CVSS Score

3.5 LOW CVSS 3.1
Attack Vector Adjacent network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability Low

Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weakness Enumeration

CWE-IDName
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')

References

URLSource
https://access.redhat.com/security/cve/CVE-2023-3748 Red Hat
https://bugzilla.redhat.com/show_bug.cgi?id=2223668 Red Hat

Git Fixes

Raw Data