← Back to CVE Index
CVE-2024-31949
Disclosed 2024-04-07
Description
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing.
Severity & CVSS Score
6.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected FRR Versions
- 9.1.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219b | GitHub |
Git Fixes
- 30a332dad86fafd2b0b6c61d23de59ed969a219b
- 2a5ea423efe179c018b836a1c5a256c93ae429ef
- 0ddeb8b0e4ad51105f56ee2bab6b629154b54a49
Raw Data
- CVE-2024-31949.cve.json — CVE record (JSON)
- CVE-2024-31949.frr.json — FRR-specific data (JSON)