Описание
Security update for frr
This update for frr fixes the following issues:
- CVE-2023-38802: Fixed bad length handling in BGP attribute handling (bsc#1213284).
- CVE-2023-41358: Fixed crash in bgpd/bgp_packet.c (bsc#1214735).
- CVE-2023-41360: Fixed out-of-bounds read in bgpd/bgp_packet.c (bsc#1214739).
- CVE-2023-3748: Fixed inifinite loop in babld message parsing may cause DoS (bsc#1213434).
- CVE-2023-41909: Fixed NULL pointer dereference due to processing in bgp_nlri_parse_flowspec (bsc#1215065).
Список пакетов
SUSE Linux Enterprise Module for Server Applications 15 SP5
openSUSE Leap 15.5
Ссылки
- Link for SUSE-SU-2023:3709-1
- E-Mail link for SUSE-SU-2023:3709-1
- SUSE Security Ratings
- SUSE Bug 1213284
- SUSE Bug 1213434
- SUSE Bug 1214735
- SUSE Bug 1214739
- SUSE Bug 1215065
- SUSE CVE CVE-2023-3748 page
- SUSE CVE CVE-2023-38802 page
- SUSE CVE CVE-2023-41358 page
- SUSE CVE CVE-2023-41360 page
- SUSE CVE CVE-2023-41909 page
Описание
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2023-3748
- SUSE Bug 1213434
Описание
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Затронутые продукты
Ссылки
- CVE-2023-38802
- SUSE Bug 1213284
Описание
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Затронутые продукты
Ссылки
- CVE-2023-41358
- SUSE Bug 1214735
Описание
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
Затронутые продукты
Ссылки
- CVE-2023-41360
- SUSE Bug 1214739
Описание
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Затронутые продукты
Ссылки
- CVE-2023-41909
- SUSE Bug 1215065