UBUNTU-CVE-2023-41909
Dashboard / Vulnerabilities / UBUNTU-CVE-2023-41909
UBUNTU-CVE-2023-41909
Summary:
Details: An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
References: https://ubuntu.com/security/CVE-2023-41909, https://github.com/FRRouting/frr/commit/cfd04dcb3e689754a72507d086ba3b9709fc5ed8, https://github.com/FRRouting/frr/commit/cc1a551cb007cc8ed8b1ea0605a7ab46c16de12b, https://github.com/FRRouting/frr/commit/0a12b878082f77b67ad5d9b4782846ac738575a2, https://github.com/FRRouting/frr/pull/13222/commits/cfd04dcb3e689754a72507d086ba3b9709fc5ed8, https://ubuntu.com/security/notices/USN-6436-1, https://www.cve.org/CVERecord?id=CVE-2023-41909
Affected packages
Package
Name: frr
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
