UbuntuUpdates.org

Package "frr"

Name: frr

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • FRRouting suite - BGP RPKI support (rtrlib)
  • FRRouting suite - SNMP support

Latest version: 8.1-1ubuntu1.9
Release: jammy (22.04)
Level: updates
Repository: universe

Links



Other versions of "frr" in Jammy

Repository Area Version
base universe 8.1-1ubuntu1
base main 8.1-1ubuntu1
security main 8.1-1ubuntu1.9
security universe 8.1-1ubuntu1.9
updates main 8.1-1ubuntu1.9

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 8.1-1ubuntu1.4 2023-06-05 16:07:27 UTC

  frr (8.1-1ubuntu1.4) jammy-security; urgency=medium

  * SECURITY UPDATE: denial of service via bgp_attr_psid_sub()
    - debian/patches/CVE-2023-31490.patch: ensure stream received has
      enough data in bgpd/bgp_attr.c.
    - CVE-2023-31490

 -- Marc Deslauriers <email address hidden> Fri, 02 Jun 2023 13:56:18 -0400

Source diff to previous version
CVE-2023-31490 An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

Version: 8.1-1ubuntu1.3 2022-12-13 02:06:21 UTC

  frr (8.1-1ubuntu1.3) jammy; urgency=medium

  * d/frr.postinst: don't change log ownership if the syslog user
    doesn't exist. Thanks to Alessandro Ratti
    <email address hidden> for the fix (LP: #1991812).

 -- Andreas Hasenack <email address hidden> Fri, 28 Oct 2022 11:38:34 -0300

Source diff to previous version
1991812 FRR deb packaging regression

Version: 8.1-1ubuntu1.2 2022-10-18 16:06:25 UTC

  frr (8.1-1ubuntu1.2) jammy-security; urgency=medium

  * SECURITY UPDATE: DoS via out-of-bounds read
    - debian/patches/CVE-2022-37032.patch: make sure hdr length is at a
      minimum of what is expected in bgpd/bgp_packet.c.
    - CVE-2022-37032
  * SECURITY UPDATE: use-after-free due to a race condition
    - debian/patches/CVE-2022-37035.patch: avoid notify race between io and
      main pthreads in bgpd/bgp_io.c, bgpd/bgp_packet.c, bgpd/bgp_packet.h.
    - CVE-2022-37035

 -- Marc Deslauriers <email address hidden> Wed, 05 Oct 2022 12:35:26 -0400

Source diff to previous version
CVE-2022-37032 An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi
CVE-2022-37035 An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible

Version: 8.1-1ubuntu1.1 2022-08-22 11:07:06 UTC

  frr (8.1-1ubuntu1.1) jammy; urgency=medium

  * Fix logging with Ubuntu's unprivileged rsyslog (LP: #1958162):
    - d/frr.postinst: change log files ownership
    - d/frr.logrotate: change rotated log file ownership

 -- Andreas Hasenack <email address hidden> Tue, 19 Jul 2022 17:36:23 -0300

1958162 syslog logging does not work



About   -   Send Feedback to @ubuntu_updates