← Back to CVE Index

CVE-2024-44070

Disclosed 2024-08-19

Description

An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.

Severity & CVSS Score

9.8 HIGH CVSS 3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected FRR Versions

  • < 8.4.6
  • < 8.5.6
  • < 9.0.4
  • < 9.1.2
  • < 10.0.2

Versions prior to 8.4 are end-of-life and no longer receive security updates.

References

URLSource
https://github.com/FRRouting/frr/pull/16497/commits/0998b38e4d61179441f90dd7e7fd6a3a8b7bd8c5 GitHub

Git Fixes

Raw Data