frr-7.5.1-7.el8.2.ML.1

エラータID: AXSA:2023-6437:06

Release date: 
Tuesday, September 26, 2023 - 03:07
Subject: 
frr-7.5.1-7.el8.2.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.

Security Fix(es):

* frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router (CVE-2023-38802)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-38802
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. frr-7.5.1-7.el8.2.ML.1.src.rpm
    MD5: 15bf7deb1f2d373c69b57db6d5ce77ca
    SHA-256: 7647e5875fe8e50fbfb35e830bbd91d292ba7ceff35b43278d0aec722249baee
    Size: 6.42 MB

Asianux Server 8 for x86_64
  1. frr-7.5.1-7.el8.2.ML.1.x86_64.rpm
    MD5: 0e08c6e8f0c85c6dcc19b5f3399f2b89
    SHA-256: fce2d7cb7d95f67623890fd5447868062943683467427b21adb31e10f8a4f691
    Size: 3.15 MB
  2. frr-selinux-7.5.1-7.el8.2.ML.1.noarch.rpm
    MD5: e8dc9d13e2d3c071d694b98ebb499f14
    SHA-256: 8c72164bb74c05fe84fb1352e691a1cce2b8ba4d4f03dcf7fad363f416aad5ec
    Size: 24.48 kB