CVE-2024-44070: Frrouting

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.

Affected products

  • Frrouting Frrouting: up to and including 10.1
  • Red Hat Enterprise Linux: version 8.0 only; version 9.0 only

Published 2024-08-19. Last modified 2026-06-17.