CVE-2023-3748 LOW

CVE-2023-3748: Inifinite loop in babld message parsing may cause dos

Vendor Red Hat
Product Red Hat Enterprise Linux 8
Weakness CWE-835
Published July 24, 2023
Last update September 27, 2024

CVSS base score

3.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.

Key dates

02Disclosure timeline

July 24, 2023 CVE published
September 27, 2024 Record updated