Out-of-bounds read in frr - CVE-2023-41360

 

Out-of-bounds read in frr - CVE-2023-41360

Published: October 3, 2023


Vulnerability identifier: #VU81446
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41360
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition in bgpd/bgp_packet.c. A remote attacker can read the initial byte of the ORF header in an ahead-of-stream situation.


Affected software

frr
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Server Applications Module
openSUSE Leap
Ubuntu
Fedora
frr (Ubuntu package)
quagga (Ubuntu package)
frr
libfrrzmq0
libfrr0-debuginfo
libfrrcares0
frr-debugsource
libfrrfpm_pb0-debuginfo
libfrrsnmp0
frr-debuginfo
libfrrospfapiclient0-debuginfo
libfrrfpm_pb0
libfrrospfapiclient0
libmlag_pb0-debuginfo
libmlag_pb0
libfrrsnmp0-debuginfo
libfrrcares0-debuginfo
libfrrzmq0-debuginfo
libfrr_pb0-debuginfo
libfrr0
frr-devel
libfrr_pb0
frr (Red Hat package)
Red Hat OpenShift Container Platform

How to mitigate CVE-2023-41360

Install updates from vendor's website.

frr - addressed in versions 8.5.3, 9.0.1
frr (Ubuntu package) - addressed in versions Ubuntu Pro, 8.1-1ubuntu1.6, 8.4.2-1ubuntu1.4
quagga (Ubuntu package) - addressed in versions Ubuntu Pro, 1.2.4-4ubuntu0.1
Red Hat OpenShift Container Platform - update to 4.17.0
frr - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrzmq0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrr0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrcares0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
frr-debugsource - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrfpm_pb0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrsnmp0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
frr-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrospfapiclient0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrfpm_pb0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrospfapiclient0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libmlag_pb0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libmlag_pb0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrsnmp0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrcares0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrrzmq0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrr_pb0-debuginfo - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrr0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
frr-devel - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
libfrr_pb0 - addressed in versions 8.4-150500.4.8.1, 8.5.6-150500.4.30.1
frr - addressed in versions 8.5.3-1.fc37, 8.5.3-1.fc38, 8.5.3-1.fc39
frr (Red Hat package) - update to 8.5.3-4.el9

External References

Related Security Bulletins