Out-of-bounds read in frr - CVE-2023-41359
Published: November 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the bgp_attr_aigp_valid() function in bgpd/bgp_attr.c. A remote attacker can send specially crafted data to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Fedora
Red Hat OpenShift Container Platform
frr
frr (Red Hat package)
How to mitigate CVE-2023-41359
Red Hat OpenShift Container Platform - update to 4.17.0
frr - addressed in versions 8.5.3-1.fc37, 8.5.3-1.fc38, 8.5.3-1.fc39
frr (Red Hat package) - update to 8.5.3-4.el9