← Back to CVE Index
CVE-2023-41359
Disclosed 2023-08-29
Description
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Severity
Critical
Affected FRR Versions
- 8.5.0 ~ 8.5.2
- 9.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/14232/commits/f96201e104892e18493f24cf67bb713678e8237b | GitHub |
Git Fixes
- f96201e104892e18493f24cf67bb713678e8237b
- d8258f9b124254f9fee3dfa79325e9d05e3e678c
- 460ee930d6dbce6e96ecbfcd568a291f31bae24e
Raw Data
- CVE-2023-41359.cve.json — CVE record (JSON)
- CVE-2023-41359.frr.json — FRR-specific data (JSON)