CVE-2023-41358 is a denial-of-service vulnerability affecting FRRouting (FRR) versions up to 9.0, specifically within the bgpd/bgp_packet.c component. The flaw allows an attacker to trigger a crash by sending malformed BGP NLRIs with a zero attribute length. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely without authentication or user interaction, leading to a complete loss of availability for affected systems. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0CPE matchmatch criteria | cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-41358
Sep 12, 2023frr: processes invalid NLRIs if attribute length is zero
Aug 29, 2023An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Aug 8, 2023