7.5
CVSSv3

CVE-2023-41909

Published: 05/09/2023 Updated: 22/12/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in FRRouting FRR up to and including 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

frrouting frrouting

debian debian linux 10.0

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in FRRouting FRR through 90 bgp_nlri_parse_flowspec in bgpd/bgp_flowspecc processes malformed requests with no attributes, leading to a NULL pointer dereference ...