← Back to CVE Index
CVE-2024-31950
Disclosed 2024-04-07
Description
In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).
Severity & CVSS Score
6.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') |
Affected FRR Versions
- 8.4.0 ~ 8.4.4
- 8.5.0 ~ 8.5.4
- 9.0.0 ~ 9.0.2
- 9.1.0
- 10.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/15674/commits/f69d1313b19047d3d83fc2b36a518355b861dfc4 | GitHub |
Git Fixes
- f69d1313b19047d3d83fc2b36a518355b861dfc4
- 1a35a2c0667b34f8472eacabde8182abb67ddee4
- 48f000ac2085e03783603071f33cf3fb46f0bfa1
- 64bf99d572f66cfc6394b0d58cca2f7fc9f28b12
- fb1020ff7d032948bd121bd1603bed41afb73e29
- 298704f1e73221172432e2a4afd79086ffcd4cca
Raw Data
- CVE-2024-31950.cve.json — CVE record (JSON)
- CVE-2024-31950.frr.json — FRR-specific data (JSON)