CVE-2024-31948
Published: 7 April 2024
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
Notes
Author | Note |
---|---|
sbeattie | the quagga project was renamed to frr |
mdeslaur | code is different in quagga, no indication it is vulnerable |
Priority
Status
Package | Release | Status |
---|---|---|
frr Launchpad, Ubuntu, Debian |
focal |
Needs triage
|
jammy |
Needed
|
|
mantic |
Needed
|
|
noble |
Needed
|
|
upstream |
Needs triage
|
|
Patches: upstream: https://github.com/FRRouting/frr/pull/15628 upstream: https://github.com/FRRouting/frr/commit/ba6a8f1a31e1a88df2de69ea46068e8bd9b97138 upstream: https://github.com/FRRouting/frr/commit/babb23b74855e23c987a63f8256d24e28c044d07 |
||
quagga Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(code not present)
|
focal |
Not vulnerable
(code not present)
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(code not present)
|