📦 Frrouting

by Frrouting

🔍 What is Frrouting?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-38406

CRITICAL CVSS 9.8 Nov 6, 2023

CVE-2023-38406 is a critical buffer overflow vulnerability in FRRouting's BGP flowspec component that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability oc...

CVE-2023-41361

CRITICAL CVSS 9.8 Aug 29, 2023

CVE-2023-41361 is a buffer overflow vulnerability in FRRouting's BGP daemon (bgpd) that occurs when processing BGP OPEN messages with overly large software version strings. Attackers can exploit this ...

CVE-2023-41359

CRITICAL CVSS 9.1 Aug 29, 2023

CVE-2023-41359 is an out-of-bounds read vulnerability in FRRouting FRR's BGP daemon that occurs during AIGP attribute validation. Attackers could exploit this to cause denial of service or potentially...

CVE-2025-61104

HIGH CVSS 7.5 Oct 28, 2025

This vulnerability in FRRouting (FRR) allows attackers to cause a denial of service by sending a specially crafted OSPF packet that triggers a NULL pointer dereference. The crash occurs in the show_vt...

CVE-2025-61107

HIGH CVSS 7.5 Oct 28, 2025

A NULL pointer dereference vulnerability in FRRouting's OSPF implementation allows attackers to crash the routing daemon via specially crafted LSA Update packets. This affects FRRouting versions 4.0 t...

CVE-2025-61101

HIGH CVSS 7.5 Oct 27, 2025

CVE-2025-61101 is a NULL pointer dereference vulnerability in FRRouting/frr that allows attackers to cause a Denial of Service (DoS) by sending a specially crafted OSPF packet. This affects FRRouting ...

CVE-2025-61105

HIGH CVSS 7.5 Oct 27, 2025

This vulnerability in FRRouting/frr allows attackers to cause a denial of service by sending a specially crafted OSPF packet that triggers a NULL pointer dereference. The crash occurs in the show_vty_...

CVE-2025-61099

HIGH CVSS 7.5 Oct 27, 2025

A NULL pointer dereference vulnerability in FRRouting's OSPF implementation allows attackers to crash the frr daemon via specially crafted LS Update packets, causing denial of service. This affects al...

CVE-2024-44070

HIGH CVSS 7.5 Aug 19, 2024

A buffer overflow vulnerability exists in FRRouting (FRR) BGP daemon where bgp_attr_encap function fails to validate stream length before processing TLV values. This allows attackers to cause denial o...

CVE-2024-34088

HIGH CVSS 7.5 Apr 30, 2024

This vulnerability in FRRouting (FRR) allows attackers to cause a denial of service by triggering a NULL pointer dereference in the OSPF daemon. When the get_edge() function returns NULL and calling f...

CVE-2023-47234

HIGH CVSS 7.5 Nov 3, 2023

A vulnerability in FRRouting FRR allows remote attackers to cause a denial of service (crash) by sending a specially crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute containing malformed NL...

CVE-2023-41909

HIGH CVSS 7.5 Sep 5, 2023

This vulnerability in FRRouting FRR allows remote attackers to cause a denial of service (crash) by sending specially crafted BGP flowspec requests with no attributes. The NULL pointer dereference in ...

CVE-2023-38802

HIGH CVSS 7.5 Aug 29, 2023

This vulnerability allows remote attackers to cause denial of service (DoS) in FRRouting and Pica8 PICOS systems by sending specially crafted BGP updates with corrupted Tunnel Encapsulation attributes...

CVE-2023-41358

HIGH CVSS 7.5 Aug 29, 2023

A NULL pointer dereference vulnerability in FRRouting's BGP daemon allows remote attackers to cause denial of service by sending specially crafted BGP packets with zero-length attributes. This affects...

CVE-2023-31490

HIGH CVSS 7.5 May 9, 2023

A vulnerability in FRRouting's BGP daemon (bgpd) allows remote attackers to cause denial of service by sending specially crafted BGP packets that trigger a flaw in the bgp_attr_psid_sub() function. Th...

CVE-2022-36440

HIGH CVSS 7.5 Apr 3, 2023

This vulnerability allows attackers to cause a denial-of-service (DoS) in FRRouting's BGP daemon by sending specially crafted BGP open packets. The reachable assertion in the peek_for_as4_capability f...

CVE-2022-26125

HIGH CVSS 7.8 Mar 3, 2022

CVE-2022-26125 is a buffer overflow vulnerability in FRRouting's IS-IS protocol implementation due to insufficient input validation of packet length. This allows attackers to potentially execute arbit...

CVE-2022-26127

HIGH CVSS 7.8 Mar 3, 2022

CVE-2022-26127 is a buffer overflow vulnerability in FRRouting's Babel routing protocol daemon that allows remote attackers to execute arbitrary code or cause denial of service. The vulnerability affe...

CVE-2022-26129

HIGH CVSS 7.8 Mar 3, 2022

CVE-2022-26129 is a buffer overflow vulnerability in FRRouting's Babel routing daemon due to improper length validation of sub-TLV fields in Babel protocol messages. Attackers can exploit this to cras...