CVE-2024-27913
CBL Mariner vulnerability analysis and mitigation

Overview

FRRouting (FRR) through version 9.1 contains a vulnerability in the ospf_te_parse_te function within ospfd/ospf_te.c that allows remote attackers to cause a denial of service condition through a malformed OSPF LSA packet. The vulnerability stems from an attempted access to a missing attribute field (NVD, Ubuntu Security).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 6.5 (Medium) with the vector string CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The issue occurs when the function attempts to create a corresponding edge from TE Link parameters. If there is no local address, an edge is created without attributes, leading to a crash when the function tries to access these non-existent attribute fields (NVD, GitHub PR).

Impact

The vulnerability can result in a denial of service condition through the crash of the ospfd daemon. The attack affects availability but does not impact confidentiality or integrity of the system (NVD).

Exploitability

The vulnerability requires an adjacent network access vector with low attack complexity. No privileges or user interaction are required to exploit this vulnerability. The attack can be executed by sending a malformed OSPF LSA packet to the target system (NVD).

Mitigation and workarounds

Fixed versions have been released for various distributions. Ubuntu has patched versions 24.04 LTS (noble), 23.10 (mantic), and 22.04 LTS (jammy). Debian has fixed the vulnerability in bullseye and sid/trixie releases. Users should upgrade to the patched versions to mitigate this vulnerability (Ubuntu Security, Debian Security).

Additional resources


SourceThis report was generated using AI

Related CBL Mariner vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55995HIGH8.7
  • Rocky Linux logoRocky Linux
  • isns-utils
NoYesJul 29, 2026
CVE-2026-59251HIGH8.7
  • CBL Mariner logoCBL Mariner
  • cpe:2.3:a:erlang:erlang\/otp
NoYesJul 27, 2026
CVE-2026-58227HIGH8.7
  • CBL Mariner logoCBL Mariner
  • cpe:2.3:a:erlang:erlang\/otp
NoYesJul 27, 2026
CVE-2026-44944HIGH8.5
  • Rocky Linux logoRocky Linux
  • iscsi-initiator-utils-debuginfo
NoYesJul 29, 2026
CVE-2026-44943MEDIUM6.9
  • Rocky Linux logoRocky Linux
  • iscsi-initiator-utils-debugsource
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management