Skip to main content

Improper Handling of Exceptional Conditions

CVE-2023-38406

Severity High
Score 9.8/10

Summary

An issue was discovered in "bgpd/bgp_flowspec.c" in FRRouting (FRR) versions prior to 8.3.2, 8.4.x prior to 8.4.3, 8.5-dev, and 9.0-dev mishandles an "nlri" length of zero, aka a "flowspec overflow."

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-755 - Improper Handling of Exceptional Conditions

The software does not handle or incorrectly handles an exceptional condition.

Advisory Timeline

  • Published