ELSA-2024-0130

ELSA-2024-0130 - frr security update

Type:SECURITY
Severity:MODERATE
Release Date:2024-01-12

Description


[7.5.1-13.3]
- Resolves: RHEL-15916 - Flowspec overflow in bgpd/bgp_flowspec.c
- Resolves: RHEL-15919 - Out of bounds read in bgpd/bgp_label.c
- Resolves: RHEL-15869 - crash from specially crafted MP_UNREACH_NLRI-containing BGP UPDATE message
- Resolves: RHEL-15868 - crash from malformed EOR-containing BGP UPDATE message


Related CVEs


CVE-2023-38407
CVE-2023-47234
CVE-2023-47235
CVE-2023-38406

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) frr-7.5.1-13.el8_9.3.src.rpme106d5908ea8873da777cc170e7ec29b-ol8_aarch64_appstream
frr-7.5.1-13.el8_9.3.aarch64.rpmeb88517c99d834687fa0de609695f111-ol8_aarch64_appstream
frr-selinux-7.5.1-13.el8_9.3.noarch.rpm714fb32a24dda207cb526cc213305143-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) frr-7.5.1-13.el8_9.3.src.rpme106d5908ea8873da777cc170e7ec29b-ol8_x86_64_appstream
frr-7.5.1-13.el8_9.3.x86_64.rpm7cacae9471b4fd24b8471f85d4e6dbea-ol8_x86_64_appstream
frr-selinux-7.5.1-13.el8_9.3.noarch.rpm714fb32a24dda207cb526cc213305143-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete