CVE-2024-44070

NameCVE-2024-44070
DescriptionAn issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3865-1, ELA-1166-1
Debian Bugs1079649

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
frr (PTS)buster, buster (lts)7.5.1-1.1+deb10u3fixed
buster (security)7.5.1-1.1+deb10u2vulnerable
bullseye7.5.1-1.1+deb11u2vulnerable
bullseye (security)7.5.1-1.1+deb11u3fixed
bookworm (security), bookworm8.4.4-1.1~deb12u1vulnerable
trixie10.1.1-0.1fixed
sid10.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
frrsourcebuster7.5.1-1.1+deb10u3ELA-1166-1
frrsourcebullseye7.5.1-1.1+deb11u3DLA-3865-1
frrsource(unstable)10.1-0.21079649

Notes

https://github.com/FRRouting/frr/pull/16497
Fixed by: https://github.com/FRRouting/frr/commit/0998b38e4d61179441f90dd7e7fd6a3a8b7bd8c5 (master)
Fixed by: https://github.com/FRRouting/frr/commit/b29169073bf38ff98fcfdd1e115a64203be13073 (frr-10.1)

Search for package or bug name: Reporting problems