ALT-PU-2023-7164-1
Package frr updated to version 9.0.1-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2023-05649
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, сетевой операционной системы Picos, операционной системы PAN-OS, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-38802
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
- https://news.ycombinator.com/item?id=37305800
- https://news.ycombinator.com/item?id=37305800
- DSA-5495
- DSA-5495
Modified: 2024-11-21
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
- https://github.com/FRRouting/frr/pull/14260
- https://github.com/FRRouting/frr/pull/14260
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
- DSA-5495
- DSA-5495
Modified: 2024-11-21
CVE-2023-41359
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
Modified: 2024-11-21
CVE-2023-41360
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
- https://github.com/FRRouting/frr/pull/14245
- https://github.com/FRRouting/frr/pull/14245
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8
Modified: 2024-11-21
CVE-2023-41361
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
Modified: 2024-11-21
CVE-2023-41909
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
- https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8
- https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- [debian-lts-announce] 20230919 [SECURITY] [DLA 3573-1] frr security update
- FEDORA-2023-ce436d56f8
- FEDORA-2023-ce436d56f8
- FEDORA-2023-514db5339e
- FEDORA-2023-514db5339e
- FEDORA-2023-61abba57d8
- FEDORA-2023-61abba57d8