Back

CRITICAL

frr: out of bounds read in bgp_attr_aigp_valid

Published Aug 29, 2023

Description

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

Affected products

Remediation

Red Hat statement

In Red Hat Enterprise Linux 8, the vulnerable code is not included. It was added in FRR-8.5 in upstream. The highest version of FRR utilized in RHEL-8 is 7.5. Hence, versions of FRR shipped with RHEL-8 are not affected by this vulnerability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 29, 2023
Updated Aug 2, 2024
Reserved Aug 29, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 29, 2023
ENISA EUVD
Assigner mitre
Published Aug 29, 2023
Updated Aug 2, 2024
Exploited since n/a
EUVD-2023-45862