CVE-2022-26129
published 2022-03-03CVE-2022-26129: Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.01%
59.6th percentile
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 8.4.1-1 (bookworm) | frr 8.4.1-1 (bookworm) |
| frrouting | frrouting | <= 8.1 | — |
| frrouting | frrouting | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Red Hat
frrouting: Buffer overflow in functions parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c
vendor_redhat·2022-02-04·CVSS 7.8
CVE-2022-26129 [HIGH] CWE-120 frrouting: Buffer overflow in functions parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c
frrouting: Buffer overflow in functions parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Package: frr (Red Hat Enterprise Linux 8) - Not affected
Package: frr (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2022-26129: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
vendor_debian·2022·CVSS 7.8
CVE-2022-26129 [HIGH] CVE-2022-26129: frr - Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong ch...
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u3)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
GHSA
GHSA-54p4-8qjr-jvgc: Buffer overflow vulnerabilities exist in FRRouting through 8
ghsa_unreviewed·2022-03-04
CVE-2022-26129 [HIGH] CWE-119 GHSA-54p4-8qjr-jvgc: Buffer overflow vulnerabilities exist in FRRouting through 8
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
OSV
CVE-2022-26129: Buffer overflow vulnerabilities exist in FRRouting through 8
osv·2022-03-03·CVSS 7.8
CVE-2022-26129 [HIGH] CVE-2022-26129: Buffer overflow vulnerabilities exist in FRRouting through 8
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-03
Published