Argh, wrong bug, previous mail was for 1036061. On Tue, Jun 13, 2023 at 03:17:52PM +0200, David Lamparter wrote: > Fixed upstream in 9f1ba873637fd6ce4a2d366eafcf41402775852b on stable/8.4 > branch.
CVE-2023-31489 / 1036062 was fixed upstream on master but not backported to 8.4 yet; now pending upstream CI & review in https://github.com/FRRouting/frr/pull/13782 8.4.4 release is expected upstream shortly, including fixes for both this and CVE-2023-31490. -equi