Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. For the stable distribution (trixie), this problem has been fixed in version 2.17.5-0+deb13u1. We recommend that you upgrade your bird2 packages.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6347-1
Fix for CVE-2024-44070. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2fff2b9a18 2024-09-20 00:43:10.627835 -------------------------------------------------------------------------------- Name : frr Product : Fedora 39 Version : 8.5.5 Release : 2.fc39 URL : http://www.frrouting.org Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2024-44070 -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 10 2024 Michal Ruprich - 8.5.5-2 - Resolves: #2305661 - Function bgpd/bgp_attr.c does not check the actual remaining stream length -------------------------------------------------------------------------------- References: [ 1 ] Bug #2305661 - CVE-2024-44070 frr: Function bgpd/bgp_attr.c does not check the actual remaining stream length [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2305661 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2fff2b9a18' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New version 8.5.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-0c063be1cc 2024-08-11 03:29:03.062220 -------------------------------------------------------------------------------- Name : frr Product : Fedora 39 Version : 8.5.5 Release : 1.fc39 URL : http://www.frrouting.org Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. -------------------------------------------------------------------------------- Update Information: New version 8.5.5 -------------------------------------------------------------------------------- ChangeLog: * Wed Jul 31 2024 Michal Ruprich - 8.5.5-1 - New version 8.5.5 * Wed Jan 3 2024 Michal Ruprich - 8.5.4-1 - New version 8.5.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273983 - CVE-2024-31948 frr: bgpd daemon crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2273983 [ 2 ] Bug #2273996 - CVE-2024-31950 frr: buffer overflow and daemon crash in ospf_te_parse_ri [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2273996 [ 3 ] Bug #2274000 - CVE-2024-31951 frr: buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2274000 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-0c063be1cc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
New version 8.5.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-61abba57d8 2023-11-15 02:14:31.347624 -------------------------------------------------------------------------------- Name : frr Product : Fedora 38 Version : 8.5.3 Release : 1.fc38 URL : https://www.frrouting.org/ Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. -------------------------------------------------------------------------------- Update Information: New version 8.5.3. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Michal Ruprich - 8.5.3-1 - New version 8.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2230983 - CVE-2023-38802 frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router https://bugzilla.redhat.com/show_bug.cgi?id=2230983 [ 2 ] Bug #2235839 - CVE-2023-41358 frr: processes invalid NLRIs if attribute length is zero https://bugzilla.redhat.com/show_bug.cgi?id=2235839 [ 3 ] Bug #2235840 - CVE-2023-41359 frr: out of bounds read in bgp_attr_aigp_valid https://bugzilla.redhat.com/show_bug.cgi?id=2235840 [ 4 ] Bug #2235842 - CVE-2023-41360 frr: ahead-of-stream read of ORF header https://bugzilla.redhat.com/show_bug.cgi?id=2235842 [ 5 ] Bug #2237416 - CVE-2023-41909 frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c https://bugzilla.redhat.com/show_bug.cgi?id=2237416 [ 6 ] Bug #2238990 - CVE-2023-31489 frr: incorrect length check inbgp_capability_llgr() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238990 [ 7 ] Bug #2238992 - CVE-2023-31490 frr: missing length check in bgp_attr_psid_sub() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-61abba57d8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New version 8.5.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ce436d56f8 2023-11-15 02:00:25.496972 -------------------------------------------------------------------------------- Name : frr Product : Fedora 37 Version : 8.5.3 Release : 1.fc37 URL : https://www.frrouting.org/ Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. -------------------------------------------------------------------------------- Update Information: New version 8.5.3. -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 9 2023 Michal Ruprich - 8.5.3-1 - New version 8.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2230983 - CVE-2023-38802 frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router https://bugzilla.redhat.com/show_bug.cgi?id=2230983 [ 2 ] Bug #2235839 - CVE-2023-41358 frr: processes invalid NLRIs if attribute length is zero https://bugzilla.redhat.com/show_bug.cgi?id=2235839 [ 3 ] Bug #2235840 - CVE-2023-41359 frr: out of bounds read in bgp_attr_aigp_valid https://bugzilla.redhat.com/show_bug.cgi?id=2235840 [ 4 ] Bug #2235842 - CVE-2023-41360 frr: ahead-of-stream read of ORF header https://bugzilla.redhat.com/show_bug.cgi?id=2235842 [ 5 ] Bug #2237416 - CVE-2023-41909 frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c https://bugzilla.redhat.com/show_bug.cgi?id=2237416 [ 6 ] Bug #2238990 - CVE-2023-31489 frr: incorrect length check inbgp_capability_llgr() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238990 [ 7 ] Bug #2238992 - CVE-2023-31490 frr: missing length check in bgp_attr_psid_sub() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ce436d56f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New version 8.5.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-514db5339e 2023-11-15 01:41:36.790714 -------------------------------------------------------------------------------- Name : frr Product : Fedora 39 Version : 8.5.3 Release : 1.fc39 URL : https://www.frrouting.org/ Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. -------------------------------------------------------------------------------- Update Information: New version 8.5.3. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Michal Ruprich - 8.5.3-1 - New version 8.5.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2230983 - CVE-2023-38802 frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router https://bugzilla.redhat.com/show_bug.cgi?id=2230983 [ 2 ] Bug #2235839 - CVE-2023-41358 frr: processes invalid NLRIs if attribute length is zero https://bugzilla.redhat.com/show_bug.cgi?id=2235839 [ 3 ] Bug #2235840 - CVE-2023-41359 frr: out of bounds read in bgp_attr_aigp_valid https://bugzilla.redhat.com/show_bug.cgi?id=2235840 [ 4 ] Bug #2235842 - CVE-2023-41360 frr: ahead-of-stream read of ORF header https://bugzilla.redhat.com/show_bug.cgi?id=2235842 [ 5 ] Bug #2237416 - CVE-2023-41909 frr: NULL pointer dereference in bgp_nlri_parse_flowspec() in bgpd/bgp_flowspec.c https://bugzilla.redhat.com/show_bug.cgi?id=2237416 [ 6 ] Bug #2238990 - CVE-2023-31489 frr: incorrect length check inbgp_capability_llgr() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238990 [ 7 ] Bug #2238992 - CVE-2023-31490 frr: missing length check in bgp_attr_psid_sub() can lead do DoS https://bugzilla.redhat.com/show_bug.cgi?id=2238992 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-514db5339e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New version 8.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-2cb0f34efe 2023-04-21 02:09:57.992813 --------------------------------------------------------------------------------Name : frr Product : Fedora 37 Version : 8.5 Release : 1.fc37 URL : https://www.frrouting.org/ Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. --------------------------------------------------------------------------------Update Information: New version 8.5 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 12 2023 Michal Ruprich - 8.5-1 - New version 8.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2177783 - New versions of frr available https://bugzilla.redhat.com/show_bug.cgi?id=2177783 [ 2 ] Bug #2184469 - CVE-2022-36440 frr: Reachable assertion in peek_for_as4_capability function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184469 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2cb0f34efe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
New version 8.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-14ec79ae02 2023-04-21 01:23:34.069315 --------------------------------------------------------------------------------Name : frr Product : Fedora 36 Version : 8.5 Release : 1.fc36 URL : https://www.frrouting.org/ Summary : Routing daemon Description : FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga. --------------------------------------------------------------------------------Update Information: New version 8.5 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 12 2023 Michal Ruprich - 8.5-1 - New version 8.5 --------------------------------------------------------------------------------References: [ 1 ] Bug #2177783 - New versions of frr available https://bugzilla.redhat.com/show_bug.cgi?id=2177783 [ 2 ] Bug #2184469 - CVE-2022-36440 frr: Reachable assertion in peek_for_as4_capability function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2184469 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-14ec79ae02' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.