CVE-2023-38283
MEDIUMOpenBGPD < 8.1 - Denial of Service via BGP Path Attribute Length Handling
Title source: llmDescription
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
References (5)
Core 5
Core References
Exploit, Third Party Advisory
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
Mailing List
https://news.ycombinator.com/item?id=37305800
Release Notes
https://www.openbsd.org/errata73.html
Scores
CVSS v3
5.3
EPSS
0.0112
EPSS Percentile
61.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-754
Status
published
Products (1)
openbgpd/openbgpd
< 8.1
Published
Aug 29, 2023
Tracked Since
Feb 18, 2026