FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Frrouting | Frrouting | 2.0 (including) | 10.4.1 (including) |
| Frr | Ubuntu | devel | * |
| Frr | Ubuntu | esm-apps/focal | * |
| Frr | Ubuntu | jammy | * |
| Frr | Ubuntu | noble | * |
| Frr | Ubuntu | plucky | * |
| Frr | Ubuntu | questing | * |
| Quagga | Ubuntu | esm-infra/bionic | * |
| Quagga | Ubuntu | esm-infra/focal | * |
| Quagga | Ubuntu | esm-infra/xenial | * |