Back

CRITICAL

frr: ahead-of-stream read of ORF header

Published Aug 29, 2023

Description

An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

Affected products

Remediation

Red Hat statement

In Red Hat Enterprise Linux 8, the vulnerable code is not included. It was added in FRR-8.4 in upstream. The highest version of FRR utilized in RHEL-8 is 7.5. Hence, versions of FRR shipped with RHEL-8 are not affected by this vulnerability. Red Hat Product Security rated this vulnerability as a LOW security impact because it only exposes the initial byte of the ORF header in an ahead-of-stream situation.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 29, 2023
Updated Oct 15, 2024
Reserved Aug 29, 2023
CISA Vulnrichment
Updated Oct 15, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 29, 2023
ENISA EUVD
Assigner mitre
Published Aug 29, 2023
Updated Oct 15, 2024
Exploited since n/a
EUVD-2023-45863