Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-34088

Опубликовано: 30 апр. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

A flaw was found in FRRouting (FRR). Some functions do not check the return value of the get_edge function in the ospfd/ospf_te.c file, allowing a NULL pointer dereference, causing a crash in the OSPF daemon, resulting in a denial of service.

Отчет

The get_edge function can return a NULL pointer when processing specially crafted link IDs or advertised router IP addresses. When the NULL pointer is returned from the get_edge function and this return value is not handled by calling functions, a NULL pointer dereference issue can be triggered. As this flaw requires a crafted link ID or advertised router IP address to create an invalid edge key can and can result only in a denial of service condition, it has been rated with a moderate severity. The FRR package as shipped in Red Hat Enterprise Linux 8 is not affected by this vulnerability because the vulnerable code was introduced in a newer version of FRR.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrNot affected
Red Hat Enterprise Linux 9frrWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-252->CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2278067frr: null pointer via get_edge() function can trigger a denial of service

EPSS

Процентиль: 21%
0.00065
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

CVSS3: 7.5
nvd
около 1 года назад

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

CVSS3: 7.5
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
около 1 года назад

In FRRouting (FRR) through 9.1, it is possible for the get_edge() func ...

CVSS3: 7.5
github
около 1 года назад

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

EPSS

Процентиль: 21%
0.00065
Низкий

7.5 High

CVSS3