FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Frrouting | Frrouting | 7.5.1 (including) | 9.0 (including) |
Picos | Pica8 | 4.3.3.2 (including) | 4.3.3.2 (including) |
Red Hat Enterprise Linux 8 | RedHat | frr-0:7.5.1-7.el8_8.2 | * |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | RedHat | frr-0:7.0-5.el8_1.1 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | frr-0:7.0-5.el8_2.1 | * |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | RedHat | frr-0:7.0-5.el8_2.1 | * |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | RedHat | frr-0:7.0-5.el8_2.1 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | frr-0:7.5-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | frr-0:7.5-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | frr-0:7.5-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | frr-0:7.5-11.el8_6.2 | * |
Red Hat Enterprise Linux 9 | RedHat | frr-0:8.3.1-5.el9_2.2 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | frr-0:8.0-5.el9_0.1 | * |
Frr | Ubuntu | esm-apps/focal | * |
Frr | Ubuntu | focal | * |
Frr | Ubuntu | jammy | * |
Frr | Ubuntu | lunar | * |
Frr | Ubuntu | upstream | * |
Quagga | Ubuntu | bionic | * |
Quagga | Ubuntu | trusty | * |
Quagga | Ubuntu | xenial | * |