bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a flowspec overflow.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Frrouting | Frrouting | * | 8.4.3 (excluding) |
Frr | Ubuntu | bionic | * |
Frr | Ubuntu | esm-apps/focal | * |
Frr | Ubuntu | focal | * |
Frr | Ubuntu | jammy | * |
Frr | Ubuntu | lunar | * |
Frr | Ubuntu | trusty | * |
Frr | Ubuntu | upstream | * |
Frr | Ubuntu | xenial | * |
Quagga | Ubuntu | bionic | * |
Quagga | Ubuntu | trusty | * |
Quagga | Ubuntu | xenial | * |
Red Hat Enterprise Linux 8 | RedHat | frr-0:7.5.1-13.el8_9.3 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | frr-0:7.5-11.el8_6.7 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | frr-0:7.5.1-7.el8_8.5 | * |
Red Hat Enterprise Linux 9 | RedHat | frr-0:8.3.1-11.el9_3.2 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | frr-0:8.0-5.el9_0.3 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | frr-0:8.3.1-5.el9_2.4 | * |