CVE Vulnerabilities

CVE-2023-38802

Improper Validation of Integrity Check Value

Published: Aug 29, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

NameVendorStart VersionEnd Version
FrroutingFrrouting7.5.1 (including)9.0 (including)
PicosPica84.3.3.2 (including)4.3.3.2 (including)
Red Hat Enterprise Linux 8RedHatfrr-0:7.5.1-7.el8_8.2*
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsRedHatfrr-0:7.0-5.el8_1.1*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatfrr-0:7.0-5.el8_2.1*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatfrr-0:7.0-5.el8_2.1*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatfrr-0:7.0-5.el8_2.1*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatfrr-0:7.5-4.el8_4.4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatfrr-0:7.5-4.el8_4.4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatfrr-0:7.5-4.el8_4.4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatfrr-0:7.5-11.el8_6.2*
Red Hat Enterprise Linux 9RedHatfrr-0:8.3.1-5.el9_2.2*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatfrr-0:8.0-5.el9_0.1*
FrrUbuntuesm-apps/focal*
FrrUbuntufocal*
FrrUbuntujammy*
FrrUbuntulunar*
FrrUbuntuupstream*
QuaggaUbuntubionic*
QuaggaUbuntutrusty*
QuaggaUbuntuxenial*

Potential Mitigations

References