FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.
Security Fix(es):
- frr: incorrect length check in bgpcapabilityllgr() can lead do DoS (CVE-2023-31489)
- frr: missing length check in bgpattrpsid_sub() can lead do DoS (CVE-2023-31490)
- frr: processes invalid NLRIs if attribute length is zero (CVE-2023-41358)
- frr: out of bounds read in bgpattraigp_valid (CVE-2023-41359)
- frr: NULL pointer dereference in bgpnlriparseflowspec() in bgpd/bgpflowspec.c (CVE-2023-41909)
- frr: mishandled malformed data leading to a crash (CVE-2023-46752)
- frr: crafted BGP UPDATE message leading to a crash (CVE-2023-46753)
- frr: ahead-of-stream read of ORF header (CVE-2023-41360)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.