← Back to CVE Index
CVE-2023-41360
Disclosed 2023-08-29
Description
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Severity & CVSS Score
9.1
CRITICAL
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-125 | Out-of-bounds Read |
Affected FRR Versions
- 8.4.x
- 8.5.0 ~ 8.5.2
- 9.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/14245/commits/9b855a692e68e0d16467e190b466b4ecb6853702 | GitHub |
Git Fixes
- 9b855a692e68e0d16467e190b466b4ecb6853702
- 6d3a96d92610983610f8303fd2067cbf9bec9f4b
- 3515178de4a56d66ed948a774efcbe4a854e1ca7
- 27de01e00aceb963439bf4d48ba94080ec1fc74f
Raw Data
- CVE-2023-41360.cve.json — CVE record (JSON)
- CVE-2023-41360.frr.json — FRR-specific data (JSON)