Open Shortest Path First (OSPF) protocol implementations may improperly determine LSA recency in affected Quagga and downstream implementations (SUSE, openSUSE, and Red Hat packages)
Published Jul 24, 2018
8.2
HIGHCVSS 3.0
EPSS 1.06%
Description
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge. In a case where the sequence numbers are the same, the LSA with the larger checksum is considered more recent, and will not be flushed from the Link State Database (LSDB). Since the RFC does not explicitly state that the values of links carried by a LSA must be the same when prematurely aging a self-originating LSA with MaxSequenceNumber, it is possible in vulnerable OSPF implementations for an attacker to craft a LSA with MaxSequenceNumber and invalid links that will result in a larger checksum and thus a 'newer' LSA that will not be flushed from the LSDB. Propagation of the crafted LSA can result in the erasure or alteration of the routing tables of routers within the routing domain, creating a denial of service condition or the re-routing of traffic on the network. CVE-2017-3224 has been reserved for Quagga and downstream implementations (SUSE, openSUSE, and Red Hat packages).
Affected products
No data.
Configuration 2
- n/a
- n/a
Configuration 3
- n/a
No data.
Red Hat Enterprise Linux 5
quagga
Will not fix
Red Hat Enterprise Linux 6
quagga
Will not fix
Red Hat Enterprise Linux 7
quagga
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | quagga | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | quagga | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | quagga | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
For an attacker to exploit this vulnerability, they would either need to control an OSPF peer or spoof a message into the routing domain that appears to come from an OSPF peer. The OSPF trust model is not considered robust against malicious or compromised peers influencing the routing table. Message spoofing is effectively prevented by requiring authentication. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
It is strongly recommended to configure Quagga to require authentication from OSPF peers (eg `ip ospf authentication message-digest `). Message digest authentication effectively prevents even a man-in-the-middle attacker from exploiting this vulnerability or otherwise interfering with the routing table, as any message without a proper cryptographic signature will be rejected.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:A/AC:M/Au:N/C:N/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.06% (0.01065) | 63.48th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.06% (0.01065) | 63.25th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.08% (0.00077) | 33.52th | v3 (v2023.03.01) |
| Jun 2, 2024 | 0.08% (0.00077) | 32.92th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00075) | 30.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.52% (0.00518) | 11.68th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.52% (0.00518) | 0.00th | v1 |
References (6)
- https://access.redhat.com/security/cve/CVE-2017-3224 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1472873 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2017-3224
- https://www.cve.org/CVERecord?id=CVE-2017-3224
- https://www.kb.cert.org/vuls/id/793496 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- https://www.quagga.net/docs/quagga.html#ip-ospf-authentication-message_002ddigest
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2017-3224 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1472873 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-3224 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-3224 | ||
| https://www.kb.cert.org/vuls/id/793496 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| https://www.quagga.net/docs/quagga.html#ip-ospf-authentication-message_002ddigest |
Change history (0)
No recorded changes yet.