CVE-2022-26125
published 2022-03-03CVE-2022-26125: Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.01%
58.9th percentile
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 8.4.1-1 (bookworm) | frr 8.4.1-1 (bookworm) |
| frrouting | frrouting | <= 8.1 | — |
| frrouting | frrouting | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9hg8-8wq3-mhhg: Buffer overflow vulnerabilities exist in FRRouting through 8
ghsa_unreviewed·2022-03-04
CVE-2022-26125 [HIGH] CWE-119 GHSA-9hg8-8wq3-mhhg: Buffer overflow vulnerabilities exist in FRRouting through 8
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
OSV
CVE-2022-26125: Buffer overflow vulnerabilities exist in FRRouting through 8
osv·2022-03-03·CVSS 7.8
CVE-2022-26125 [HIGH] CVE-2022-26125: Buffer overflow vulnerabilities exist in FRRouting through 8
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
Red Hat
frrouting: overflow bugs in unpack_tlv_router_cap
vendor_redhat·2022-02-06·CVSS 7.8
CVE-2022-26125 [HIGH] CWE-1284 frrouting: overflow bugs in unpack_tlv_router_cap
frrouting: overflow bugs in unpack_tlv_router_cap
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
frrouting is vulnerable to a flaw that can cause buffer overflow through due to incorrect checks on the input packet length when processing type-length-value packets. There is high impact to availability due to the fact that the process up-time can be made unreliable.
Package: frr (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2022-26125: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
vendor_debian·2022·CVSS 7.8
CVE-2022-26125 [HIGH] CVE-2022-26125: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-03
Published