← Back to CVE Index

CVE-2023-38802

Disclosed 2023-08-29

Description

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

Severity

High

Affected FRR Versions

  • < 8.5.3
  • 9.0.0

Versions prior to 8.4 are end-of-life and no longer receive security updates.

References

URLSource
https://github.com/FRRouting/frr/pull/14290/commits/bcb6b58d9530173df41d3a3cbc4c600ee0b4b186 GitHub

Git Fixes

Raw Data