← Back to CVE Index
CVE-2024-31948
Disclosed 2024-04-07
Description
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
Severity & CVSS Score
6.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input |
Affected FRR Versions
- 8.4.0 ~ 8.4.4
- 8.5.0 ~ 8.5.4
- 9.0.0 ~ 9.0.2
- 9.1.0
- 10.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/15628/commits/ba6a8f1a31e1a88df2de69ea46068e8bd9b97138 | GitHub |
Git Fixes
- ba6a8f1a31e1a88df2de69ea46068e8bd9b97138
- 81b536bff94cb44f3ae726e83b041faa9e203654
- 1cf60e53a4c841f179f9a7ebc79e810dcd15056f
- 0486f4f04dd1338dbfb5fb1cb4ae09d4be8f11ae
- 51679e4504546584d98673b76ed8e12a8bc74fe0
- 9b0d3e7ce4ff1e4ed70639f49b8da583c20b41cc
Raw Data
- CVE-2024-31948.cve.json — CVE record (JSON)
- CVE-2024-31948.frr.json — FRR-specific data (JSON)