← Back to CVE Index
CVE-2024-31951
Disclosed 2024-04-07
Description
In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).
Severity & CVSS Score
6.5
HIGH
CVSS 3.1
Attack Vector
Adjacent network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') |
Affected FRR Versions
- 8.4.0 ~ 8.4.4
- 8.5.0 ~ 8.5.4
- 9.0.0 ~ 9.0.2
- 9.1.0
- 10.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/15674/commits/5557a289acdaeec8cc63ffc97b5c2abf6dee7b3a | GitHub |
Git Fixes
- 5557a289acdaeec8cc63ffc97b5c2abf6dee7b3a
- f1ffec340fa23540f438576db69d46000310a3f8
- aa1237612cb26f38ccda1eb7725aedd46524d221
- fc77daa322580961f2f18afb4747e9f33a36cb67
- fcb339c4ea3134b977cebc910c45ad5bf0992feb
- 4e70b09f24b72fbb27ff5eda63393bfd2a72ef37
Raw Data
- CVE-2024-31951.cve.json — CVE record (JSON)
- CVE-2024-31951.frr.json — FRR-specific data (JSON)