CVE-2022-36440
published 2023-04-03CVE-2022-36440: A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.62%
73.4th percentile
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | frr | < frr 8.4.1-1 (bookworm) | frr 8.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| frrouting | frrouting | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cpmq-crvm-2w5p: A reachable assertion was found in Frrouting frr-bgpd 8
ghsa_unreviewed·2023-04-03
CVE-2022-36440 [HIGH] CWE-617 GHSA-cpmq-crvm-2w5p: A reachable assertion was found in Frrouting frr-bgpd 8
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
OSV
CVE-2022-36440: A reachable assertion was found in Frrouting frr-bgpd 8
osv·2023-04-03·CVSS 7.5
CVE-2022-36440 [HIGH] CVE-2022-36440: A reachable assertion was found in Frrouting frr-bgpd 8
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Red Hat
frr: Reachable assertion in peek_for_as4_capability function
vendor_redhat·2023-04-04·CVSS 7.5
CVE-2022-36440 [HIGH] CWE-617 frr: Reachable assertion in peek_for_as4_capability function
frr: Reachable assertion in peek_for_as4_capability function
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
A reachable assertion flaw was found in Frrouting frr-bgpd in the peek_for_as4_capability function. This flaw allows an attacker to maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in a denial of service.
Package: frr (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-36440: frr - A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_...
vendor_debian·2022·CVSS 7.5
CVE-2022-36440 [HIGH] CVE-2022-36440: frr - A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_...
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u2)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/spwpun/pocshttps://github.com/spwpun/pocs/blob/main/frr-bgpd.mdhttps://lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HU4PKLUVB5CTMOVQ2GV33TNUNMJCBGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBXEXL2ZQBWCBLNUP6P67FHECXQWSK3L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GM66PNHGCXZU66LQCTP2FSJLFF6CVMSI/https://www.debian.org/security/2023/dsa-5495https://github.com/spwpun/pocshttps://github.com/spwpun/pocs/blob/main/frr-bgpd.mdhttps://lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HU4PKLUVB5CTMOVQ2GV33TNUNMJCBGD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBXEXL2ZQBWCBLNUP6P67FHECXQWSK3L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GM66PNHGCXZU66LQCTP2FSJLFF6CVMSI/https://www.debian.org/security/2023/dsa-5495
2023-04-03
Published