Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40261.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-40261
Upstream
Published
2024-04-30T19:15:23Z
Modified
2026-04-01T05:13:59.749824Z
Summary
CVE-2024-34088 affecting package frr for versions less than 8.5.3-6
Details

In FRRouting (FRR) through 9.1, it is possible for the getedge() function in ospfte.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

References

Affected packages

Azure Linux:2 / frr

Package

Name
frr
Purl
pkg:rpm/azure-linux/frr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.5.3-6

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-40261.json"