In FRR, the internet routing protocol suite software, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. . From: Arturo Borrero Gonzalez To:
# OpenBGPD 7.9 * Include OpenBSD 7.2 errata 023: Incorrect length checks allow an out-of-bounds read in `bgpd(8)`.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-c804000502 2023-04-04 01:33:05.702054 --------------------------------------------------------------------------------Name : openbgpd Product : Fedora 37 Version : 7.9 Release : 1.fc37 URL : https://www.openbgpd.org/ Summary : OpenBGPD Routing Daemon Description : OpenBGPD is a free implementation of the Border Gateway Protocol (BGP), Version 4. It allows ordinary machines to be used as routers exchanging routes with other systems speaking the BGP protocol. --------------------------------------------------------------------------------Update Information: # OpenBGPD 7.9 * Include OpenBSD 7.2 errata 023: Incorrect length checks allow an out-of-bounds read in `bgpd(8)`. --------------------------------------------------------------------------------ChangeLog: * Thu Mar 23 2023 Robert Scheck 7.9-1 - Upgrade to 7.9 (#2181220) --------------------------------------------------------------------------------References: [ 1 ] Bug #2181220 - openbgpd-7.9 is available https://bugzilla.redhat.com/show_bug.cgi?id=2181220 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c804000502' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.