diff options
| author | Zhang Peng <peng.zhang1.cn@windriver.com> | 2025-10-28 14:13:22 +0800 |
|---|---|---|
| committer | Gyorgy Sarvari <skandigraun@gmail.com> | 2025-10-29 16:59:21 +0100 |
| commit | 50c69deb2c01cdf49bf4a1e8b68949f00cb31f82 (patch) | |
| tree | ddc26ba672c53e097020f966f1653785fc7a612a /meta-python/recipes-devtools/python/python3-django_4.2.17.bb | |
| parent | d2da8450c03adf1066a81313dcc47fda53e8afed (diff) | |
| download | meta-openembedded-50c69deb2c01cdf49bf4a1e8b68949f00cb31f82.tar.gz | |
frr: fix CVE-2024-31949
CVE-2024-31949:
In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability
as a dynamic capability because malformed data results in a pointer not advancing.
Reference:
[https://nvd.nist.gov/vuln/detail/CVE-2024-31949]
[https://salsa.debian.org/lts-team/packages/frr/-/blob/debian/7.5.1-1.1+deb10u4/debian/patches/CVE-2024-31949.patch?ref_type=tags]
Upstream patches:
[https://github.com/FRRouting/frr/pull/15640/commits/30a332dad86fafd2b0b6c61d23de59ed969a219b]
Signed-off-by: Zhang Peng <peng.zhang1.cn@windriver.com>
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-django_4.2.17.bb')
0 files changed, 0 insertions, 0 deletions
