CVE-2024-34088

HIGH

FRRouting < 9.1 - Denial of Service via NULL Pointer Dereference in OSPF get_edge Function

Title source: llm
STIX 2.1

Description

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.

Scores

CVSS v3 7.5
EPSS 0.0069
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (1)
frrouting/frrouting < 9.1
Published Apr 30, 2024
Tracked Since Feb 18, 2026