← Back to CVE Index
CVE-2023-46753
Disclosed 2023-11-03
Description
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
Severity
High
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-863 | Incorrect Authorization |
Affected FRR Versions
- < 8.5.4
- 9.0.0 ~ 9.0.1
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/d8482bf011cb2b173e85b65b4bf3d5061250cdb9 | GitHub |
Git Fixes
- d8482bf011cb2b173e85b65b4bf3d5061250cdb9
- 6cca03a52e047f1271807ac501b08b3a4f5ad344
- 77e4046de0c602fcaad249909a99fbc037ac5c6b
- 21418d64af11553c402f932b0311c812d98ac3e4
- 3cc271a39f0e05b9478413ec6425d4ad0daf0932
Raw Data
- CVE-2023-46753.cve.json — CVE record (JSON)
- CVE-2023-46753.frr.json — FRR-specific data (JSON)