diff options
author | Yi Zhao <yi.zhao@windriver.com> | 2023-08-28 18:49:18 +0800 |
---|---|---|
committer | Armin Kuster <akuster808@gmail.com> | 2023-08-31 08:49:13 -0400 |
commit | 32e47b26e93a9e17e53e928ca6df073c453b1bc3 (patch) | |
tree | b7dabcafd19de144901c19e4efc380f5b15fad43 /meta-python/recipes-devtools/python/python3-crcmod/0001-setup.py-use-setuptools-instead-of-distutils.patch | |
parent | b0ba472191c2b7709ef04ae9c5a23bea040518f9 (diff) | |
download | meta-openembedded-32e47b26e93a9e17e53e928ca6df073c453b1bc3.tar.gz |
frr: Security fix CVE-2023-3748
CVE-2023-3748:
A flaw was found in FRRouting when parsing certain babeld unicast hello
messages that are intended to be ignored. This issue may allow an
attacker to send specially crafted hello messages with the unicast flag
set, the interval field set to 0, or any TLV that contains a sub-TLV
with the Mandatory flag set to enter an infinite loop and cause a denial
of service.
Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-3748
Patch from:
https://github.com/FRRouting/frr/commit/ae1e0e1fed77716bc06f181ad68c4433fb5523d0
Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit ee1026ab77dcb31b0f5cb723b4d998aab4c00382)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-crcmod/0001-setup.py-use-setuptools-instead-of-distutils.patch')
0 files changed, 0 insertions, 0 deletions