ELSA-2023-2202

ELSA-2023-2202 - frr security, bug fix, and enhancement update

Type:SECURITY
Severity:MODERATE
Release Date:2023-05-15

Description


[8.3.1-5]
- Resolves: #2147522 - It is not possible to run FRR as a non-root user

[8.3.1-4]
- Resolves: #2144500 - AVC error when reloading FRR with provided reload script

[8.3.1-3]
- Related: #2129743 - Adding missing rules for vtysh and other daemons

[8.3.1-2]
- Resolves: #2128738 - out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service

[8.3.1-1]
- Resolves: #2129731 - Rebase FRR to the latest version
- Resolves: #2129743 - Add targeted SELinux policy for FRR
- Resolves: #2127494 - BGP incorrectly withdraws routes on graceful restart capable routers


Related CVEs


CVE-2022-37032

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 9 (aarch64) frr-8.3.1-5.el9.src.rpm5cb16aee1dcfb837aa1eaa82254f0764-
frr-8.3.1-5.el9.aarch64.rpm9a29b2dccbac6acd81c1d18fc5079600-
frr-selinux-8.3.1-5.el9.noarch.rpmccc251ba1ca9cea115e8af112e8c49b1-
Oracle Linux 9 (x86_64) frr-8.3.1-5.el9.src.rpm5cb16aee1dcfb837aa1eaa82254f0764-
frr-8.3.1-5.el9.x86_64.rpm2a15a587d07f7c28334bcb3dedf77f78-
frr-selinux-8.3.1-5.el9.noarch.rpmccc251ba1ca9cea115e8af112e8c49b1-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete