Debian dsa-6322 : frr - security update

low Nessus Plugin ID 318679

Synopsis

The remote Debian host is missing one or more security-related updates.

Description

The remote Debian 12 / 13 host has packages installed that are affected by multiple vulnerabilities as referenced in the dsa-6322 advisory.

- ------------------------------------------------------------------------- Debian Security Advisory DSA-6322-1 [email protected] https://www.debian.org/security/ Aron Xu June 05, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : frr CVE ID : CVE-2023-3748 CVE-2024-27913 CVE-2024-31950 CVE-2024-31951 CVE-2024-34088 CVE-2025-61099 CVE-2025-61100 CVE-2025-61101 CVE-2025-61102 CVE-2025-61103 CVE-2025-61104 CVE-2025-61105 CVE-2025-61106 CVE-2025-61107 CVE-2026-5107 CVE-2026-28532 CVE-2026-37457 CVE-2026-37458 Debian Bug :

Several vulnerabilities were discovered in FRRouting (frr), a suite of internet routing protocol daemons. A remote attacker could trigger these issues by sending specially crafted protocol packets to a vulnerable daemon, resulting in denial of service (infinite loops, NULL pointer dereferences and crashes) or potentially the execution of arbitrary code through out-of-bounds reads and writes and buffer overflows. The flaws affect packet and attribute parsing in the BGP daemon (including FlowSpec, EVPN/VNC NLRI and MP_REACH_NLRI handling), the OSPF daemon (Traffic Engineering, Segment Routing and Opaque LSA processing) and the babeld daemon.

For the oldstable distribution (bookworm), these problems have been fixed in version 8.4.4-1.1~deb12u2.

For the stable distribution (trixie), these problems have been fixed in version 10.3-3+deb13u1.

We recommend that you upgrade your frr packages.

For the detailed security status of frr please refer to its security tracker page at:
https://security-tracker.debian.org/tracker/frr

Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/

Mailing list: [email protected]

Tenable has extracted the preceding description block directly from the Debian security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the frr packages.

See Also

https://security-tracker.debian.org/tracker/source-package/frr

https://packages.debian.org/source/bookworm/frr

https://security-tracker.debian.org/tracker/CVE-2024-34088

https://security-tracker.debian.org/tracker/CVE-2024-27913

https://security-tracker.debian.org/tracker/CVE-2024-31950

https://security-tracker.debian.org/tracker/CVE-2024-31951

https://security-tracker.debian.org/tracker/CVE-2023-3748

https://security-tracker.debian.org/tracker/CVE-2025-61099

https://security-tracker.debian.org/tracker/CVE-2025-61100

https://security-tracker.debian.org/tracker/CVE-2025-61101

https://security-tracker.debian.org/tracker/CVE-2025-61102

https://security-tracker.debian.org/tracker/CVE-2025-61103

https://security-tracker.debian.org/tracker/CVE-2025-61104

https://security-tracker.debian.org/tracker/CVE-2025-61105

https://security-tracker.debian.org/tracker/CVE-2025-61106

https://security-tracker.debian.org/tracker/CVE-2025-61107

https://security-tracker.debian.org/tracker/CVE-2026-5107

https://security-tracker.debian.org/tracker/CVE-2026-37457

https://security-tracker.debian.org/tracker/CVE-2026-28532

https://security-tracker.debian.org/tracker/CVE-2026-37458

https://packages.debian.org/source/trixie/frr

Plugin Details

Severity: Low

ID: 318679

File Name: debian_DSA-6322.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 6/4/2026

Updated: 6/4/2026

Supported Sensors: Continuous Assessment, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Low

Base Score: 3.6

Temporal Score: 2.8

Vector: CVSS2#AV:N/AC:H/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2026-5107

CVSS v3

Risk Factor: Medium

Base Score: 4.2

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Low

Base Score: 2.3

Threat Score: 1.3

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:frr-pythontools, p-cpe:/a:debian:debian_linux:frr-snmp, p-cpe:/a:debian:debian_linux:frr, p-cpe:/a:debian:debian_linux:frr-doc, p-cpe:/a:debian:debian_linux:frr-rpki-rtrlib, cpe:/o:debian:debian_linux:12.0, cpe:/o:debian:debian_linux:13.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/5/2026

Vulnerability Publication Date: 7/24/2023

Reference Information

CVE: CVE-2023-3748, CVE-2024-27913, CVE-2024-31950, CVE-2024-31951, CVE-2024-34088, CVE-2025-61099, CVE-2025-61100, CVE-2025-61101, CVE-2025-61102, CVE-2025-61103, CVE-2025-61104, CVE-2025-61105, CVE-2025-61106, CVE-2025-61107, CVE-2026-28532, CVE-2026-37457, CVE-2026-37458, CVE-2026-5107