{"id":"CVE-2023-38283","details":"In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.","modified":"2026-08-12T03:51:27.457845482Z","published":"2023-08-29T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38283.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig"},{"type":"WEB","url":"https://github.com/openbgpd-portable/openbgpd-portable/releases/tag/8.1"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=37305800"},{"type":"WEB","url":"https://www.openbsd.org/errata73.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38283.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38283"},{"type":"ARTICLE","url":"https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openbgpd-portable/openbgpd-portable","events":[{"introduced":"0"},{"fixed":"889ed3953f0cba6ba512c4bfa87c7e2aa3f48586"}],"database_specific":{"cpe":"cpe:2.3:a:openbgpd:openbgpd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"8.1"}],"source":["DESCRIPTION","CPE_RANGE","REFERENCES"]}}],"versions":["8.0","7.9","7.8","7.7","7.6","7.5","7.4","7.3","7.2","7.1","7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38283.json"}}],"schema_version":"1.9.0"}