CVE-2024-34088

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*

History

01 May 2025, 14:48

Type Values Removed Values Added
First Time Frrouting frrouting
Frrouting
CPE cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*
References () https://github.com/FRRouting/frr/pull/15674/commits/34d704fb0ea60dc5063af477a2c11d4884984d4f - () https://github.com/FRRouting/frr/pull/15674/commits/34d704fb0ea60dc5063af477a2c11d4884984d4f - Patch

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/FRRouting/frr/pull/15674/commits/34d704fb0ea60dc5063af477a2c11d4884984d4f - () https://github.com/FRRouting/frr/pull/15674/commits/34d704fb0ea60dc5063af477a2c11d4884984d4f -

20 Nov 2024, 17:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) En FRRouting (FRR) hasta 9.1, es posible que la función get_edge() en ospf_te.c en el demonio OSPF devuelva un puntero NULL. En los casos en que las funciones de llamada no manejan el valor NULL devuelto, el daemon OSPF falla, lo que lleva a la denegación de servicio.
CWE CWE-476

30 Apr 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-30 19:15

Updated : 2025-05-01 14:48


NVD link : CVE-2024-34088

Mitre link : CVE-2024-34088

CVE.ORG link : CVE-2024-34088


JSON object : View

Products Affected

frrouting

  • frrouting
CWE
CWE-476

NULL Pointer Dereference