[CLSA-2025:1762420748] frr: Fix of 4 CVEs
Type:
security
Severity:
Important
Release date:
2025-11-06 09:19:11 UTC
Description:
- CVE-2023-41358: fix crash when processing NLRIs with zero attribute length - CVE-2023-47235: fix EOR handling to avoid unwanted processing of malformed attributes - CVE-2023-46753: fix mandatory attributes check for UPDATE messages with unknown transit attributes - CVE-2023-47234: fix handling NLRIs when MP_UNREACH_NLRI received without mandatory attributes
Updated packages:
  • frr-8.3.1-5.el9.2.alma.tuxcare.els3.x86_64.rpm
    sha:82badefda4b7bfb37de2cfdbfaf554bd9303cd45f799a570434365b34aeedf3a
  • frr-selinux-8.3.1-5.el9.2.alma.tuxcare.els3.noarch.rpm
    sha:7c84bbadff714f32ea6ce29a1245517fab04db11622c32aaf2b19b1865867873
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.