Buffer Overflow Vulnerability in FRRouting OSPF Parser
CVE-2024-31950

6.5MEDIUM

Key Information:

Vendor

FRRouting

Status
Vendor
CVE Published:
7 April 2024

What is CVE-2024-31950?

A buffer overflow vulnerability exists in the FRRouting software, specifically in the OSPF parser for LSA packets. This issue arises from improper handling of Segment Routing subTLVs, where the size of the subTLVs is not validated during processing. An attacker could exploit this vulnerability by sending specially crafted OSPF LSA packets, which may cause the FRRouting daemon to crash, resulting in a denial of service. Users of FRRouting, particularly those operating with version 9.1, are advised to implement recommended updates to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.