• Home
  • Disclosure Policy
  • FRRouting CVEs
NetDEF
Home Disclosure Policy FRRouting CVEs
← Back to CVE Index

CVE-2023-38406

Disclosed 2023-11-06

Description

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

References

URLSource
https://github.com/FRRouting/frr/pull/12884 GitHub
https://github.com/FRRouting/frr/compare/frr-8.4.2...frr-8.4.3 GitHub
https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html Debian

Git Fixes

  • 0b999c886e241c52bd1f7ef0066700e4b618ebb3
  • 7a23a1b9f15b41b9360b180de97fe621b0b6d2ab
  • 8a4e6637fc0621e90daa4decb4ee887a0af8ee24
  • 8d69743e81656163c652cc2e938f386752a93554
  • 5a9e18cbfdc9f10ad6b7a390719b093bb5a4fc5d
  • 2fa384a90163bab6692f6a5ac05b97d33eb3da60

Raw Data

  • CVE-2023-38406.cve.json — CVE record (JSON)
  • CVE-2023-38406.frr.json — FRR-specific data (JSON)
NetDEF CVE Numbering Authority
Home NetDEF
Last Updated on Tue Jul 14 11:11:24 PM UTC 2026 (Git Hash: production@8f553c9)