Tuesday, September 17, 2024

[USN-7016-1] FRR vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmbprzYACgkQZWnYVadE
vpNDCw/8CsZNUiIac76UJuZkkgoE+phcYKUE1xWZAlba72FyBqB/2cXqDAmRzHAk
h73oTaHtIE94eDPCinFas2ozDwGp2d7/zXbZ5xHiuaE6MtR1alT/ozfbdBfWTz4H
/Y5yqqMy888BFlyI7dGpY/D72mqzpoTNAoBwQ4vQk7V9n8LuDkTCFnRltoZq1BkG
nBrRa/qud5DMzajTiciUJ1Y04u5dhO73i9rM34Memm4i1Zi2iRdAroMU5VzRKwCR
26penB7CWHSP2M5oUcQ//YkFzaJ2IEm8y5zjK38xDdsolO+MyRykuEFXV0UkefKD
8xwZBzXEAoTqCcX3+RADXhQs/vns3zeiy0wvvvYegPxxhp5qP4YfdWFVuGbmfrub
oxdt62cn/4lCEeU3j6/xLEygOgT0k3N8iJ3HChgE7FMcQmwOfUIaIpjjfXKDJQyy
wULNsOUGaFCOuRp6y509rEs5m5NTDQJCriJdN7f43yLrQeBR0Q4WoZrRm9CMIu6+
DvuQBGc8LTTQsdFT8xfGmEQUqzFCMlMhOvDrvFAwrLkgMUiIs6D+cYzs17J+/e+4
I2CEy2C0jLnhiGfnoR1c/LQ+cN11lfHEplAkffiwADx5DElLrP4NZLWNCIvXFVy7
UdwwTy33IfsX6D2CfIVIyyMhZOeKIICOXgG4YNPAy47BC1QZmcc=
=UEgt
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-7016-1
September 17, 2024

frr vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

FRR could be made to crash if it received specially crafted network
traffic.

Software Description:
- frr: FRRouting suite of internet protocols

Details:

Iggy Frankovic discovered that FRR incorrectly handled certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
frr 8.4.4-1.1ubuntu6.2

Ubuntu 22.04 LTS
frr 8.1-1ubuntu1.11

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-7016-1
CVE-2024-44070

Package Information:
https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu6.2
https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.11

No comments:

Post a Comment