7.5
CVSSv3

CVE-2023-31490

Published: 09/05/2023 Updated: 21/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue found in Frrouting bgpd v.8.4.2 allows a remote malicious user to cause a denial of service via the bgp_attr_psid_sub() function.

Vulnerable Product Search on Vulmon Subscribe to Product

frrouting frrouting 8.4.2

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1036062 frr: CVE-2023-31490 Package: src:frr; Maintainer for src:frr is David Lamparter <equinox-debian@diac24net>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 May 2023 19:51:01 UTC Severity: grave Tags: security, upstream Found in version frr/842-1 Forwarded t ...
Multiple vulnerabilities were discovered in frr, the FRRouting suite of internet protocols, while processing malformed requests and packets the BGP daemon may have reachable assertions, NULL pointer dereference, out-of-bounds memory access, which may lead to denial of service attack For the oldstable distribution (bullseye), these problems have be ...