An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Frrouting | Frrouting | * | 9.0 (including) |
| Red Hat Enterprise Linux 8 | RedHat | frr-0:7.5.1-22.el8 | * |
| Red Hat Enterprise Linux 9 | RedHat | frr-0:8.5.3-4.el9 | * |
| Frr | Ubuntu | bionic | * |
| Frr | Ubuntu | esm-apps/focal | * |
| Frr | Ubuntu | focal | * |
| Frr | Ubuntu | jammy | * |
| Frr | Ubuntu | lunar | * |
| Frr | Ubuntu | trusty | * |
| Frr | Ubuntu | upstream | * |
| Frr | Ubuntu | xenial | * |
| Quagga | Ubuntu | bionic | * |
| Quagga | Ubuntu | trusty | * |
| Quagga | Ubuntu | xenial | * |