CVE-2023-38283
Dashboard / Vulnerabilities / CVE-2023-38283
CVE-2023-38283
Summary:
Details: In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
References: https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig, https://github.com/openbgpd-portable/openbgpd-portable/releases/tag/8.1, https://news.ycombinator.com/item?id=37305800, https://www.openbsd.org/errata73.html, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38283.json, https://nvd.nist.gov/vuln/detail/CVE-2023-38283, https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
Affected packages
Package
Name:
Purl:
