Lucene search

K
oraclelinuxOracleLinuxELSA-2024-0130
HistoryJan 12, 2024 - 12:00 a.m.

frr security update

2024-01-1200:00:00
linux.oracle.com
9
frr
security update
rhel-15916
rhel-15919
rhel-15869
rhel-15868
bgpd
flowspec
out of bounds read
crash
bgp_update message
unix

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.3%

[7.5.1-13.3]

  • Resolves: RHEL-15916 - Flowspec overflow in bgpd/bgp_flowspec.c
  • Resolves: RHEL-15919 - Out of bounds read in bgpd/bgp_label.c
  • Resolves: RHEL-15869 - crash from specially crafted MP_UNREACH_NLRI-containing BGP UPDATE message
  • Resolves: RHEL-15868 - crash from malformed EOR-containing BGP UPDATE message

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

27.3%