CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-55553

High Severity
SVRS
68/100

CVSSv3
7.5/10

EPSS
0.0015/1

CVE-2024-55553 is a vulnerability in FRRouting (FRR) that can be exploited to impact route handling performance. This issue arises when the size of updates received via RTR exceeds the socket buffer, triggering re-validation of all routes. Although the CVSS score is 7.5, the SVRS score of 68 highlights a tangible risk, especially since it's tagged as "In The Wild." An attacker can deliberately cause a high volume of route updates to continuously trigger re-validation, potentially overwhelming FRR routers, especially those with large routing tables. This can lead to increased BMP traffic and impact the route handling performance of all FRR instances using RPKI globally. This denial-of-service condition makes timely patching crucial. Versions 10.0.3, 10.1.2, 10.2.1, and 10.3 and later contain the fix.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:N
I:N
A:H
2025-01-06

2025-01-23

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

USN-7230-2: FRR vulnerabilities
2025-01-28
USN-7230-2: FRR vulnerabilities | Iggy Frankovic discovered that FRR incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2024-44070) It was discovered that FRR re-validated all routes in certain instances when the internal socket's buffer size overflowed. A remote attacker could possibly use this issue to impact the performance of FRR, resulting in a denial of service. (CVE-2024-55553)
cve-2024-44070
cve-2024-55553
ubuntu
messages
CVE-2024-55553 | Frrouting up to 10.2 RIB Revalidation resource consumption
vuldb.com2025-01-07
CVE-2024-55553 | Frrouting up to 10.2 RIB Revalidation resource consumption | A vulnerability classified as problematic has been found in Frrouting up to 10.2. Affected is an unknown function of the component RIB Revalidation. The manipulation leads to resource consumption. This vulnerability is traded as CVE-2024-55553. Access to the local network is required for this attack. There is no exploit available. It
vuldb.com
rss
forum
news

Social Media

CVE-2024-55553 Denial of Service via RPKI Updates in FRRouting pre-10.3 In FRRouting (FRR) versions before 10.3, attackers can cause repeated RIB revalidation. This happens by sending around 500 RPKI updates. It ... https://t.co/RV33Xvo2SB
0
0
0
CVE-2024-55553 In FRRouting (FRR) before 10.3, it is possible for an attacker to trigger repeated RIB revalidation by sending approximately 500 RPKI updates, potentially leading to … https://t.co/E7zthfLZ8k
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://frrouting.org/security/cve-2024-55553/
[email protected]https://github.com/FRRouting/frr/pull/17586/commits/b0800bfdf04b4fcf48504737ebfe4ba7f05268d3
AF854A3A-2127-422B-91AE-364DA2661108https://lists.debian.org/debian-lts-announce/2025/01/msg00023.html
[email protected]https://frrouting.org/security/cve-2024-55553/
[email protected]https://github.com/FRRouting/frr/pull/17586/commits/b0800bfdf04b4fcf48504737ebfe4ba7f05268d3

CWE Details

CWE IDCWE NameDescription
CWE-404Improper Resource Shutdown or ReleaseThe program does not release or incorrectly releases a resource before it is made available for re-use.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence