CVE-2023-38802: Debian Linux
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
- Frrouting Frrouting: from 7.5.1, up to and including 9.0
- PICA8 Picos: version 4.3.3.2 only
Published 2023-08-29. Last modified 2026-06-17.