A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2023-3748 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2223668 Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2023-07-24T15:19:20.511Z

Updated: 2024-01-23T01:05:10.544Z

Reserved: 2023-07-18T12:45:44.867Z


Link: CVE-2023-3748

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-07-24T16:15:13.203

Modified: 2023-11-07T04:19:28.013


Link: CVE-2023-3748

JSON object: View

cve-icon Redhat Information

No data.

CWE