home tags events about login
one honk maybe more

benjojo posted 29 Aug 2023 10:51 +0000

At last, a blog post that has been in the works for a while. Something that started as a small investigation and uncovered what I believe to be potentially near internet breaking flaws in how some BGP implementations works.

This is: CVE-2023-4481 (Juniper), CVE-2023-38802 (FRR), CVE-2023-38283 (OpenBSD), CVE-2023-40457 (EXOS)


"Grave flaws in BGP Error handling"

https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling

A broken fuse, with "Grave flaws in BGP Error handling" written on under it