Bug 1214738 (CVE-2023-41359) - VUL-0: CVE-2023-41359: quagga,frr: Out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c
Summary: VUL-0: CVE-2023-41359: quagga,frr: Out-of-bounds read in bgp_attr_aigp_valid ...
Status: RESOLVED INVALID
Alias: CVE-2023-41359
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/376585/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-29 08:33 UTC by Cathy Hu
Modified: 2023-08-31 16:02 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-08-29 08:33:30 UTC
CVE-2023-41359

An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds
read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the
availability of two bytes during AIGP validation.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-41359
https://www.cve.org/CVERecord?id=CVE-2023-41359
https://github.com/FRRouting/frr/pull/14232
Comment 1 Cathy Hu 2023-08-29 08:35:52 UTC
I think the issue was introduced with this commit in frr version 8.5: https://github.com/FRRouting/frr/commit/97a52c82a569f4a2ba792fbd734f5e635a057e6f

We dont have 8.5 yet, so tracking as not affected:
- SUSE:SLE-11-SP1:Update/quagga  0.99.15
- SUSE:SLE-12-SP2:Update/quagga  1.1.1  
- SUSE:SLE-15:Update/quagga      1.1.1
- SUSE:SLE-15-SP4:Update/quagga  1.1.1
 
- SUSE:SLE-15-SP3:Update/frr     7.4  
- SUSE:SLE-15-SP5:Update/frr     8.4    

Please let me know in case you have concerns, thanks :)
Comment 3 Cathy Hu 2023-08-31 16:02:35 UTC
closing