Buffer Overflow Vulnerability in FRRouting OSPF Link Parser
CVE-2024-31951

6.5MEDIUM

Key Information:

Vendor

FRRouting

Status
Vendor
CVE Published:
7 April 2024

What is CVE-2024-31951?

A buffer overflow vulnerability exists in FRRouting's Opaque LSA Extended Link parser, specifically in the ospf_te_parse_ext_link function. This issue arises when the parser processes OSPF LSA packets, leading to potential daemon crashes as the lengths of Segment Routing Adjacency SID subTLVs are not properly validated. Network administrators are advised to implement patches promptly to mitigate risks associated with this vulnerability, ensuring the stability and security of their routing protocols.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.