← Back to CVE Index
CVE-2023-38802
Disclosed 2023-08-29
Description
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Severity
High
Affected FRR Versions
- < 8.5.3
- 9.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/14290/commits/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186 | GitHub |
Git Fixes
- bcb6b58d9530173df41d3a3cbc4c600ee0b4b186
- 3a68c969621e15e6050efa2f35e49995cb0dfb0b
- 8a4a88c46d15004b1a584cd47f9f6b8278f8da66
- 46817adab03802355c3cce7b753c7a735bdcc5ae
Raw Data
- CVE-2023-38802.cve.json — CVE record (JSON)
- CVE-2023-38802.frr.json — FRR-specific data (JSON)