Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2024:4090-1 important: frr Security Fixes and Threats

suse
Calendar Grey November 28, 2024
Dist Suse Esm H88
Essential security upgrades for frr on SUSE: addresses various vulnerabilities with significant patches. Take immediate action.
* jsc#PED-11092 Cross-References: * CVE-2023-31489 * CVE-2023-31490

Summary

## This update for frr fixes the following issues: Update to frr 8.5.6 (jsc#PED-PED-11092) including fixes for: * CVE-2024-44070,CVE-2024-34088,CVE-2024-31951,CVE-2024-31950, CVE-2024-31948,CVE-2024-27913,CVE-2023-47235,CVE-2023-47234, CVE-2023-46753,CVE-2023-46752,CVE-2023-41909,CVE-2023-41360, CVE-2023-41358,CVE-2023-38802,CVE-2023-38407,CVE-2023-38406, CVE-2023-3748,CVE-2023-31490,CVE-2023-31489 and other bugfixes. See https://frrouting.org/release/8.5.6/ for details. The most recent frr 8.x series provides several new features, improvements and bug fixes for various protocols and daemons, especially for PIM/PIMv6/BGP and VRF support. See https://frrouting.org/release/8.5/ for details and links. ## Patch Instructions:

References

* jsc#PED-11092

Cross-

* CVE-2023-31489

* CVE-2023-31490

* CVE-2023-3748

* CVE-2023-38406

* CVE-2023-38407

* CVE-2023-38802

* CVE-2023-41358

* CVE-2023-41360

* CVE-2023-41909

* CVE-2023-46752

* CVE-2023-46753

* CVE-2023-47234

* CVE-2023-47235

* CVE-2024-27913

* CVE-2024-31948

* CVE-2024-31950

* CVE-2024-31951

* CVE-2024-34088

* CVE-2024-44070

CVSS scores:

* CVE-2023-31489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-31489 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2023-31490 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-31490 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-3748 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:4090-1
Release Date: 2024-11-28T07:58:02Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here