ALT-PU-2024-1200-1
Package frr updated to version 9.0.2-alt1 for branch sisyphus_riscv64.
Closed vulnerabilities
BDU:2023-08243
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-08631
Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-46752
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
- https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35
- https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-46753
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
- https://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9
- https://github.com/FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-47234
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).
- https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf
- https://github.com/FRRouting/frr/pull/14716/commits/c37119df45bbf4ef713bc10475af2ee06e12f3bf
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
Modified: 2024-11-21
CVE-2023-47235
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
- https://github.com/FRRouting/frr/pull/14716/commits/6814f2e0138a6ea5e1f83bdd9085d9a77999900b
- https://github.com/FRRouting/frr/pull/14716/commits/6814f2e0138a6ea5e1f83bdd9085d9a77999900b
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update
- [debian-lts-announce] 20240428 [SECURITY] [DLA 3797-1] frr security update