FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
https://cert-portal.siemens.com/productcert/html/ssa-455250.html
https://www.debian.org/security/2023/dsa-5495
https://news.ycombinator.com/item?id=37305800
https://lists.debian.org/debian-lts-announce/2023/09/msg00020.html
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling