VYPR
Unrated severityNVD Advisory· Published Aug 29, 2023· Updated Oct 2, 2024

CVE-2023-41376

CVE-2023-41376

Description

Nokia SR OS 22.10 and SR Linux mishandle BGP path attributes when error-handling update-fault-tolerance is disabled, enabling DoS via malformed BGP updates.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Nokia SR OS 22.10 and SR Linux mishandle BGP path attributes when error-handling update-fault-tolerance is disabled, enabling DoS via malformed BGP updates.

Vulnerability

Nokia Service Router Operating System (SR OS) version 22.10 and SR Linux mishandle BGP path attributes when the error-handling update-fault-tolerance feature is not enabled [1]. This improper handling occurs during the processing of malformed or corrupted BGP path attributes, which can lead to unintended behaviour.

Exploitation

An attacker who is a BGP peer can send a crafted BGP UPDATE message containing a malformed path attribute to a vulnerable Nokia router [1]. The router, lacking the protective update-fault-tolerance configuration, will mishandle the attribute. No additional authentication or user interaction is required beyond establishing a BGP session, which typically relies on TCP and optional MD5 or TCP-AO authentication. The attacker must be able to inject the malicious update into the BGP session.

Impact

Successful exploitation can cause the affected BGP session to reset or behave unpredictably [1], resulting in a denial of service (DoS) for routes learned via that session. This can lead to route flapping, network instability, and potential loss of connectivity. The impact is primarily on availability, but integrity of routing information may also be affected if the mishandling leads to incorrect route propagation.

Mitigation

The vulnerability is mitigated by enabling the error-handling update-fault-tolerance configuration on the router [1]. As of the publication date (2023-08-29), no software patch has been released; the workaround is to adjust the configuration. Users should ensure this feature is enabled in their BGP configuration. The affected versions are SR OS 22.10 and SR Linux; users of these versions should apply the configuration change.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.