CVE-2023-38406

medium
Published 2024-01-25 Β· Modified 2024-01-10
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."

Predictions

Exploit likelihood
20%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description ffr: Flowspec overflow in bgpd/bgp_flowspec.c Red Hat statement Red Hat OpenStack Platform does not ship its own version of the frr package, instead using the version from the underlying Red Hat Enterprise Linux. RHOSP is marked as Not Affected as no changes need to be made by the OpenStack engineering team. System administrators of OpenStack deployments should apply updates once…

Description

ffr: Flowspec overflow in bgpd/bgp_flowspec.c

Red Hat statement

Red Hat OpenStack Platform does not ship its own version of the frr package, instead using the version from the underlying Red Hat Enterprise Linux. RHOSP is marked as Not Affected as no changes need to be made by the OpenStack engineering team. System administrators of OpenStack deployments should apply updates once available in RHEL.

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 8frr-0:7.5.1-13.el8_9.3RHSA-2024:01302024-01-10T00:00:00Z
Red Hat Enterprise Linux 8.6 Extended Update Supportfrr-0:7.5-11.el8_6.7RHSA-2024:11132024-03-05T00:00:00Z
Red Hat Enterprise Linux 8.8 Extended Update Supportfrr-0:7.5.1-7.el8_8.5RHSA-2024:05742024-01-30T00:00:00Z
Red Hat Enterprise Linux 9frr-0:8.3.1-11.el9_3.2RHSA-2024:04772024-01-25T00:00:00Z
Red Hat Enterprise Linux 9.0 Extended Update Supportfrr-0:8.0-5.el9_0.3RHSA-2024:11522024-03-05T00:00:00Z
Red Hat Enterprise Linux 9.2 Extended Update Supportfrr-0:8.3.1-5.el9_2.4RHSA-2024:10932024-03-05T00:00:00Z

Apply commands

bash fix
Apply RHSA-2024:0130 for Red Hat Enterprise Linux 8
yum update -y frr
# or:
dnf upgrade -y frr

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 8.4.4-1
sid Fixed 8.4.4-1
forky Fixed 8.4.4-1
bullseye Fixed 7.5.1-1.1+deb11u3
bookworm Fixed 8.4.4-1.1~deb12u1
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.