MEDIUM
frr: mishandled malformed data leading to a crash
Published Oct 26, 2023
5.9
MEDIUMCVSS 3.1
EPSS 0.85%
Description
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
frr-0:7.5.1-22.el8
Fixed · RHSA-2024:2981
Red Hat Enterprise Linux 9
frr-0:8.5.3-4.el9
Fixed · RHSA-2024:2156
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | frr-0:7.5.1-22.el8 | Fixed | RHSA-2024:2981 |
| Red Hat Enterprise Linux 9 | frr-0:8.5.3-4.el9 | Fixed | RHSA-2024:2156 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Weaknesses (1)
References (8)
- https://access.redhat.com/security/cve/CVE-2023-46752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2246379 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-50919 Advisory
- https://github.com/FRRouting/frr/pull/14645/commits/b08afc81c60607a4f736f418f2e3eb06087f1a35 Patch
- https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/09/msg00007.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-46752
- https://www.cve.org/CVERecord?id=CVE-2023-46752
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 26, 2023
Updated Nov 4, 2025
Reserved Oct 26, 2023
Link CVE-2023-46752
CISA Vulnrichment
Updated Sep 9, 2024
ENISA EUVD
EUVD-2023-50919 Assigner mitre
Published Oct 26, 2023
Updated Nov 4, 2025
Exploited since n/a
Link EUVD-2023-50919