Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:1971-1

Опубликовано: 10 июн. 2024
Источник: suse-cvrf

Описание

Security update for frr

This update for frr fixes the following issues:

  • CVE-2024-34088: Fixed null pointer via get_edge() function can trigger a denial of service (bsc#1223786).
  • CVE-2024-31951: Fixed buffer overflow in ospf_te_parse_ext_link (bsc#1222528).
  • CVE-2024-31950: Fixed buffer overflow and daemon crash in ospf_te_parse_ri (bsc#1222526).

Список пакетов

SUSE Linux Enterprise Module for Server Applications 15 SP5
frr-8.4-150500.4.23.1
frr-devel-8.4-150500.4.23.1
libfrr0-8.4-150500.4.23.1
libfrr_pb0-8.4-150500.4.23.1
libfrrcares0-8.4-150500.4.23.1
libfrrfpm_pb0-8.4-150500.4.23.1
libfrrospfapiclient0-8.4-150500.4.23.1
libfrrsnmp0-8.4-150500.4.23.1
libfrrzmq0-8.4-150500.4.23.1
libmlag_pb0-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP6
frr-8.4-150500.4.23.1
frr-devel-8.4-150500.4.23.1
libfrr0-8.4-150500.4.23.1
libfrr_pb0-8.4-150500.4.23.1
libfrrcares0-8.4-150500.4.23.1
libfrrfpm_pb0-8.4-150500.4.23.1
libfrrospfapiclient0-8.4-150500.4.23.1
libfrrsnmp0-8.4-150500.4.23.1
libfrrzmq0-8.4-150500.4.23.1
libmlag_pb0-8.4-150500.4.23.1
openSUSE Leap 15.5
frr-8.4-150500.4.23.1
frr-devel-8.4-150500.4.23.1
libfrr0-8.4-150500.4.23.1
libfrr_pb0-8.4-150500.4.23.1
libfrrcares0-8.4-150500.4.23.1
libfrrfpm_pb0-8.4-150500.4.23.1
libfrrospfapiclient0-8.4-150500.4.23.1
libfrrsnmp0-8.4-150500.4.23.1
libfrrzmq0-8.4-150500.4.23.1
libmlag_pb0-8.4-150500.4.23.1
openSUSE Leap 15.6
frr-8.4-150500.4.23.1
frr-devel-8.4-150500.4.23.1
libfrr0-8.4-150500.4.23.1
libfrr_pb0-8.4-150500.4.23.1
libfrrcares0-8.4-150500.4.23.1
libfrrfpm_pb0-8.4-150500.4.23.1
libfrrospfapiclient0-8.4-150500.4.23.1
libfrrsnmp0-8.4-150500.4.23.1
libfrrzmq0-8.4-150500.4.23.1
libmlag_pb0-8.4-150500.4.23.1

Описание

In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.4-150500.4.23.1

Ссылки

Описание

In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.4-150500.4.23.1

Ссылки

Описание

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.4-150500.4.23.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.4-150500.4.23.1

Ссылки