• Home
  • Disclosure Policy
  • FRRouting CVEs
NetDEF
Home Disclosure Policy FRRouting CVEs
← Back to CVE Index

CVE-2023-41358

Disclosed 2023-08-29

Description

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

References

URLSource
https://github.com/FRRouting/frr/pull/14260 GitHub
https://www.debian.org/security/2023/dsa-5495 Debian
https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html Debian
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LMJNX44SMJM25JZO7XWHDQCOB4SNJPIE/ Fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JLG64IF3FU7V76K4TKCCXVNEE6P2VUDO/ Fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WXR6PIVY4SWO7HDT4EY733H4X32SCPM4/ Fedora

Git Fixes

  • 28ccc24d38df1d51ed8a563507e5d6f6171fdd38
  • 669af8d76e83eff813767eed19bea6b7059347b1
  • f291f1ee9434f56d4b185db0652794a92e313b00
  • e515434439007cbc25da2cea48b7192fbc497d5b

Raw Data

  • CVE-2023-41358.cve.json — CVE record (JSON)
  • CVE-2023-41358.frr.json — FRR-specific data (JSON)
NetDEF CVE Numbering Authority
Home NetDEF
Last Updated on Tue Jul 14 11:11:24 PM UTC 2026 (Git Hash: production@8f553c9)