CVE-2023-38802: Debian Linux

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

Affected products

  • Debian Debian Linux: version 10.0 only; version 11.0 only; version 12.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Frrouting Frrouting: from 7.5.1, up to and including 9.0
  • PICA8 Picos: version 4.3.3.2 only

Published 2023-08-29. Last modified 2026-06-17.