<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for frr</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:4090-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-11-28T07:57:59Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-11-28T07:57:59Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-11-28T07:57:59Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for frr</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for frr fixes the following issues:

Update to frr 8.5.6 (jsc#PED-PED-11092) including fixes for:

- CVE-2024-44070,CVE-2024-34088,CVE-2024-31951,CVE-2024-31950,
  CVE-2024-31948,CVE-2024-27913,CVE-2023-47235,CVE-2023-47234,
  CVE-2023-46753,CVE-2023-46752,CVE-2023-41909,CVE-2023-41360,
  CVE-2023-41358,CVE-2023-38802,CVE-2023-38407,CVE-2023-38406,
  CVE-2023-3748,CVE-2023-31490,CVE-2023-31489 and other bugfixes.
  See https://frrouting.org/release/8.5.6/ for details.

The most recent frr 8.x series provides several new features,
improvements and bug fixes for various protocols and daemons,
especially for PIM/PIMv6/BGP and VRF support.

See https://frrouting.org/release/8.5/ for details and links.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2024-4090,SUSE-SLE-Module-Server-Applications-15-SP5-2024-4090,SUSE-SLE-Module-Server-Applications-15-SP6-2024-4090,openSUSE-SLE-15.5-2024-4090,openSUSE-SLE-15.6-2024-4090</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      <Description>Link for SUSE-SU-2024:4090-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2024-November/019857.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:4090-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-31489/</URL>
      <Description>SUSE CVE CVE-2023-31489 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-31490/</URL>
      <Description>SUSE CVE CVE-2023-31490 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-3748/</URL>
      <Description>SUSE CVE CVE-2023-3748 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-38406/</URL>
      <Description>SUSE CVE CVE-2023-38406 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-38407/</URL>
      <Description>SUSE CVE CVE-2023-38407 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-38802/</URL>
      <Description>SUSE CVE CVE-2023-38802 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-41358/</URL>
      <Description>SUSE CVE CVE-2023-41358 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-41360/</URL>
      <Description>SUSE CVE CVE-2023-41360 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-41909/</URL>
      <Description>SUSE CVE CVE-2023-41909 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-46752/</URL>
      <Description>SUSE CVE CVE-2023-46752 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-46753/</URL>
      <Description>SUSE CVE CVE-2023-46753 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-47234/</URL>
      <Description>SUSE CVE CVE-2023-47234 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-47235/</URL>
      <Description>SUSE CVE CVE-2023-47235 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-27913/</URL>
      <Description>SUSE CVE CVE-2024-27913 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-31948/</URL>
      <Description>SUSE CVE CVE-2024-31948 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-31950/</URL>
      <Description>SUSE CVE CVE-2024-31950 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-31951/</URL>
      <Description>SUSE CVE CVE-2024-31951 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-34088/</URL>
      <Description>SUSE CVE CVE-2024-34088 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-44070/</URL>
      <Description>SUSE CVE CVE-2024-44070 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Server Applications 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5" CPE="cpe:/o:suse:sle-module-server-applications:15:sp5">SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Server Applications 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6" CPE="cpe:/o:suse:sle-module-server-applications:15:sp6">SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.5">
      <Branch Type="Product Name" Name="openSUSE Leap 15.5">
        <FullProductName ProductID="openSUSE Leap 15.5" CPE="cpe:/o:opensuse:leap:15.5">openSUSE Leap 15.5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="frr-8.5.6-150500.4.30.1">
      <FullProductName ProductID="frr-8.5.6-150500.4.30.1">frr-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="frr-devel-8.5.6-150500.4.30.1">
      <FullProductName ProductID="frr-devel-8.5.6-150500.4.30.1">frr-devel-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrr0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrr0-8.5.6-150500.4.30.1">libfrr0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrr_pb0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrr_pb0-8.5.6-150500.4.30.1">libfrr_pb0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrrcares0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrrcares0-8.5.6-150500.4.30.1">libfrrcares0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrrfpm_pb0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrrfpm_pb0-8.5.6-150500.4.30.1">libfrrfpm_pb0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrrospfapiclient0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrrospfapiclient0-8.5.6-150500.4.30.1">libfrrospfapiclient0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrrsnmp0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrrsnmp0-8.5.6-150500.4.30.1">libfrrsnmp0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libfrrzmq0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libfrrzmq0-8.5.6-150500.4.30.1">libfrrzmq0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libmlag_pb0-8.5.6-150500.4.30.1">
      <FullProductName ProductID="libmlag_pb0-8.5.6-150500.4.30.1">libmlag_pb0-8.5.6-150500.4.30.1</FullProductName>
    </Branch>
    <Relationship ProductReference="frr-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1">frr-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-devel-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1">frr-devel-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1">libfrr0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1">libfrr_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrcares0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1">libfrrcares0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrfpm_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1">libfrrfpm_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrospfapiclient0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1">libfrrospfapiclient0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrsnmp0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1">libfrrsnmp0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrzmq0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1">libfrrzmq0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmlag_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1">libmlag_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1">frr-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-devel-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1">frr-devel-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1">libfrr0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1">libfrr_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrcares0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1">libfrrcares0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrfpm_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1">libfrrfpm_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrospfapiclient0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1">libfrrospfapiclient0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrsnmp0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1">libfrrsnmp0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrzmq0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1">libfrrzmq0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmlag_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Server Applications 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1">libmlag_pb0-8.5.6-150500.4.30.1 as a component of SUSE Linux Enterprise Module for Server Applications 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1">frr-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-devel-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1">frr-devel-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1">libfrr0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1">libfrr_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrcares0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1">libfrrcares0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrfpm_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1">libfrrfpm_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrospfapiclient0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1">libfrrospfapiclient0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrsnmp0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1">libfrrsnmp0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrzmq0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1">libfrrzmq0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmlag_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1">libmlag_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1">frr-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="frr-devel-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1">frr-devel-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1">libfrr0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrr_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1">libfrr_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrcares0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1">libfrrcares0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrfpm_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1">libfrrfpm_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrospfapiclient0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1">libfrrospfapiclient0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrsnmp0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1">libfrrsnmp0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libfrrzmq0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1">libfrrzmq0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libmlag_pb0-8.5.6-150500.4.30.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1">libmlag_pb0-8.5.6-150500.4.30.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.</Note>
    </Notes>
    <CVE>CVE-2023-31489</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-31489.html</URL>
        <Description>CVE-2023-31489</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211248</URL>
        <Description>SUSE Bug 1211248</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.</Note>
    </Notes>
    <CVE>CVE-2023-31490</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-31490.html</URL>
        <Description>CVE-2023-31490</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211249</URL>
        <Description>SUSE Bug 1211249</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2023-3748</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-3748.html</URL>
        <Description>CVE-2023-3748</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1213434</URL>
        <Description>SUSE Bug 1213434</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."</Note>
    </Notes>
    <CVE>CVE-2023-38406</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-38406.html</URL>
        <Description>CVE-2023-38406</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216900</URL>
        <Description>SUSE Bug 1216900</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing.</Note>
    </Notes>
    <CVE>CVE-2023-38407</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-38407.html</URL>
        <Description>CVE-2023-38407</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216899</URL>
        <Description>SUSE Bug 1216899</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).</Note>
    </Notes>
    <CVE>CVE-2023-38802</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-38802.html</URL>
        <Description>CVE-2023-38802</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1213284</URL>
        <Description>SUSE Bug 1213284</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.</Note>
    </Notes>
    <CVE>CVE-2023-41358</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-41358.html</URL>
        <Description>CVE-2023-41358</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1214735</URL>
        <Description>SUSE Bug 1214735</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.</Note>
    </Notes>
    <CVE>CVE-2023-41360</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-41360.html</URL>
        <Description>CVE-2023-41360</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1214739</URL>
        <Description>SUSE Bug 1214739</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2023-41909</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-41909.html</URL>
        <Description>CVE-2023-41909</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1215065</URL>
        <Description>SUSE Bug 1215065</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.</Note>
    </Notes>
    <CVE>CVE-2023-46752</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-46752.html</URL>
        <Description>CVE-2023-46752</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216627</URL>
        <Description>SUSE Bug 1216627</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.</Note>
    </Notes>
    <CVE>CVE-2023-46753</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-46753.html</URL>
        <Description>CVE-2023-46753</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216626</URL>
        <Description>SUSE Bug 1216626</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).</Note>
    </Notes>
    <CVE>CVE-2023-47234</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-47234.html</URL>
        <Description>CVE-2023-47234</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216897</URL>
        <Description>SUSE Bug 1216897</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.</Note>
    </Notes>
    <CVE>CVE-2023-47235</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-47235.html</URL>
        <Description>CVE-2023-47235</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1216896</URL>
        <Description>SUSE Bug 1216896</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.</Note>
    </Notes>
    <CVE>CVE-2024-27913</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-27913.html</URL>
        <Description>CVE-2024-27913</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1220548</URL>
        <Description>SUSE Bug 1220548</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.</Note>
    </Notes>
    <CVE>CVE-2024-31948</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-31948.html</URL>
        <Description>CVE-2024-31948</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1222518</URL>
        <Description>SUSE Bug 1222518</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).</Note>
    </Notes>
    <CVE>CVE-2024-31950</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-31950.html</URL>
        <Description>CVE-2024-31950</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1222526</URL>
        <Description>SUSE Bug 1222526</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated).</Note>
    </Notes>
    <CVE>CVE-2024-31951</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-31951.html</URL>
        <Description>CVE-2024-31951</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1222528</URL>
        <Description>SUSE Bug 1222528</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service.</Note>
    </Notes>
    <CVE>CVE-2024-34088</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-34088.html</URL>
        <Description>CVE-2024-34088</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1223786</URL>
        <Description>SUSE Bug 1223786</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.</Note>
    </Notes>
    <CVE>CVE-2024-44070</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Server Applications 15 SP6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.5:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrr_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrcares0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrfpm_pb0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrospfapiclient0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrsnmp0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libfrrzmq0-8.5.6-150500.4.30.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libmlag_pb0-8.5.6-150500.4.30.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244090-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-44070.html</URL>
        <Description>CVE-2024-44070</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1229438</URL>
        <Description>SUSE Bug 1229438</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
