HomeDefectsLIN1023-1416
Fixed

LIN1023-1416 : Security Advisory - frr - CVE-2023-3748

Created: Jul 20, 2023    Updated: Sep 28, 2023
Resolved Date: Sep 20, 2023
Found In Version: 10.23.30.1
Fix Version: 10.23.30.2
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

https://nvd.nist.gov/vuln/detail/CVE-2023-3748

CVEs