← Back to CVE Index
CVE-2024-44070
Disclosed 2024-08-19
Description
An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
Severity & CVSS Score
9.8
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected FRR Versions
- < 8.4.6
- < 8.5.6
- < 9.0.4
- < 9.1.2
- < 10.0.2
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/16497/commits/0998b38e4d61179441f90dd7e7fd6a3a8b7bd8c5 | GitHub |
Git Fixes
- 0998b38e4d61179441f90dd7e7fd6a3a8b7bd8c5
- b29169073bf38ff98fcfdd1e115a64203be13073
- 094c35715a336446eaf225c0d68052c476488846
- 21cd931a5f9303e12104c72ce31ca383c0c57514
- ab70eee423cce4a06103f52cb4a2e3bd2740afa2
- 237e56054e765d62849ae444e68d16d9eeb19640
- ca92b815458afd5b9f35b6240ce804046637ab25
Raw Data
- CVE-2024-44070.cve.json — CVE record (JSON)
- CVE-2024-44070.frr.json — FRR-specific data (JSON)