← Back to CVE Index
CVE-2024-34088
Disclosed 2024-04-30
Description
In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-476 | NULL Pointer Dereference |
Affected FRR Versions
- 8.4.0 ~ 8.4.4
- 8.5.0 ~ 8.5.4
- 9.0.0 ~ 9.0.2
- 9.1.0
- 10.0.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/15674/commits/8c177d69e32b91b45bda5fc5da6511fa03dc11ca | GitHub |
Git Fixes
- 8c177d69e32b91b45bda5fc5da6511fa03dc11ca
- c7ef95210c4715cbe3e2ecae875c1bc423069d16
- cef38442420aeac8e163f8aa55f1b985908f993c
- 6520a6f4d1abbeca253b11a4fbbe2662e917ca69
- 4b753fd134773962773210812d0afd07061a8183
- 26ea8574cd3c0c2447be30b47ee908bd3d707c38
Raw Data
- CVE-2024-34088.cve.json — CVE record (JSON)
- CVE-2024-34088.frr.json — FRR-specific data (JSON)