
Cloud Vulnerability DB
A community-led vulnerabilities database
FRRouting (FRR) through version 9.1 contains a vulnerability in the ospf_te_parse_te function within ospfd/ospf_te.c that allows remote attackers to cause a denial of service condition through a malformed OSPF LSA packet. The vulnerability stems from an attempted access to a missing attribute field (NVD, Ubuntu Security).
The vulnerability has been assigned a CVSS v3.1 Base Score of 6.5 (Medium) with the vector string CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue occurs when the function attempts to create a corresponding edge from TE Link parameters. If there is no local address, an edge is created without attributes, leading to a crash when the function tries to access these non-existent attribute fields (NVD, GitHub PR).
The vulnerability can result in a denial of service condition through the crash of the ospfd daemon. The attack affects availability but does not impact confidentiality or integrity of the system (NVD).
The vulnerability requires an adjacent network access vector with low attack complexity. No privileges or user interaction are required to exploit this vulnerability. The attack can be executed by sending a malformed OSPF LSA packet to the target system (NVD).
Fixed versions have been released for various distributions. Ubuntu has patched versions 24.04 LTS (noble), 23.10 (mantic), and 22.04 LTS (jammy). Debian has fixed the vulnerability in bullseye and sid/trixie releases. Users should upgrade to the patched versions to mitigate this vulnerability (Ubuntu Security, Debian Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."