Vulnerabilities > CVE-2023-38406 - Improper Handling of Exceptional Conditions vulnerability in Frrouting
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/FRRouting/frr/compare/frr-8.4.2...frr-8.4.3
- https://github.com/FRRouting/frr/compare/frr-8.4.2...frr-8.4.3
- https://github.com/FRRouting/frr/pull/12884
- https://github.com/FRRouting/frr/pull/12884
- https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html
- https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html