Input validation error in frr - CVE-2024-27913

 

Input validation error in frr - CVE-2024-27913

Published: November 28, 2024


Vulnerability identifier: #VU101031
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-27913
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of OSPF LSA packets within the ospf_te_parse_te() function in ospfd/ospf_te.c. A remote attacker can send specially crafted packets to the server and crash the ospfd daemon.


Affected software

frr
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
Server Applications Module
openSUSE Leap
Ubuntu
frr (Ubuntu package)
frr
libfrr0
libfrrzmq0-debuginfo
libfrrsnmp0-debuginfo
libmlag_pb0
libmlag_pb0-debuginfo
libfrr_pb0-debuginfo
libfrrfpm_pb0
libfrrzmq0
libfrr0-debuginfo
frr-debugsource
libfrrcares0-debuginfo
frr-devel
libfrrospfapiclient0
libfrrcares0
libfrrospfapiclient0-debuginfo
libfrr_pb0
libfrrsnmp0
frr-debuginfo
libfrrfpm_pb0-debuginfo

How to mitigate CVE-2024-27913

Install updates from vendor's website.

frr - addressed in versions 9.0.3, 9.1.1
frr (Ubuntu package) - addressed in versions 8.1-1ubuntu1.9, 8.4.4-1.1ubuntu1.3
frr - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrr0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrzmq0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrsnmp0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libmlag_pb0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libmlag_pb0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrr_pb0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrfpm_pb0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrzmq0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrr0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
frr-debugsource - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrcares0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
frr-devel - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrospfapiclient0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrcares0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrospfapiclient0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrr_pb0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrsnmp0 - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
frr-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1
libfrrfpm_pb0-debuginfo - addressed in versions 8.4-150500.4.20.1, 8.5.6-150500.4.30.1

External References

Related Security Bulletins