CVE-2022-37032
published 2022-09-19CVE-2022-37032: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in…
PriorityP341critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.58%
72.7th percentile
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | frr | < frr 8.4.1-1 (bookworm) | frr 8.4.1-1 (bookworm) |
| frrouting | frrouting | < 8.4 | 8.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2024-06-05·CVSS 7.8
CVE-2022-37035 [HIGH] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: FRR could be made to crash or run programs if it received
specially crafted network traffic.
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
Instructions: After a standard system update you need to re
Ubuntu
Quagga vulnerabilities
vendor_ubuntu·2023-11-15
CVE-2022-37032 Quagga vulnerabilities
Title: Quagga vulnerabilities
Summary: Quagga could be made to crash if it received specially crafted network
traffic.
It was discovered that Quagga incorrectly handled certain BGP messages. A
remote attacker could possibly use this issue to cause Quagga to crash,
resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2022-10-18·CVSS 9.1
CVE-2022-37032 [CRITICAL] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled parsing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. (CVE-2022-37032)
It was discovered that FRR incorrectly handled processing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service, obtain sensitive information,
or execute arbitrary code. (CVE-2022-37035)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service
vendor_redhat·2022-09-20·CVSS 9.1
CVE-2022-37032 [CRITICAL] CWE-125 frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service
frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
A vulnerability was found in FRRouting. This issue occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c. An out-of-bounds read in the BGP daemon may lead to a segmentation fault and a denial of service.
Debian
CVE-2022-37032: frr - An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to ...
vendor_debian·2022·CVSS 9.1
CVE-2022-37032 [CRITICAL] CVE-2022-37032: frr - An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to ...
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Scope: local
bookworm: resolved (fixed in 8.4.1-1)
bullseye: resolved (fixed in 7.5.1-1.1+deb11u1)
forky: resolved (fixed in 8.4.1-1)
sid: resolved (fixed in 8.4.1-1)
trixie: resolved (fixed in 8.4.1-1)
OSV
frr vulnerabilities
osv·2024-06-05·CVSS 7.8
CVE-2022-26126 [HIGH] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled certain network traffic.
A remote attacker could possibly use this issue to cause FRR to crash,
resulting in a denial of service. (CVE-2022-26126, CVE-2022-26127,
CVE-2022-26128, CVE-2022-26129, CVE-2022-37032, CVE-2022-37035,
CVE-2023-31490, CVE-2023-38406, CVE-2023-38407, CVE-2023-46752,
CVE-2023-46753, CVE-2023-47234, CVE-2023-47235, CVE-2024-31948)
Ben Cartwright-Cox discovered that FRR incorrectly handled certain
network traffic. A remote attacker could possibly use this issue to cause
FRR to crash, resulting in a denial of service. (CVE-2023-38802)
OSV
frr vulnerabilities
osv·2022-10-18·CVSS 9.1
CVE-2022-37032 [CRITICAL] frr vulnerabilities
frr vulnerabilities
It was discovered that FRR incorrectly handled parsing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. (CVE-2022-37032)
It was discovered that FRR incorrectly handled processing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service, obtain sensitive information,
or execute arbitrary code. (CVE-2022-37035)
GHSA
GHSA-mxrw-2vpr-fpwr: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8
ghsa_unreviewed·2022-09-20
CVE-2022-37032 [CRITICAL] CWE-125 GHSA-mxrw-2vpr-fpwr: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
OSV
CVE-2022-37032: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8
osv·2022-09-19·CVSS 9.1
CVE-2022-37032 [CRITICAL] CVE-2022-37032: An out-of-bounds read in the BGP daemon of FRRouting FRR before 8
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1202023https://github.com/FRRouting/frr/commit/6d58272b4cf96f0daa846210dd2104877900f921https://github.com/FRRouting/frr/commit/ff6db1027f8f36df657ff2e5ea167773752537edhttps://lists.debian.org/debian-lts-announce/2022/11/msg00039.htmlhttps://www.debian.org/security/2023/dsa-5362https://bugzilla.suse.com/show_bug.cgi?id=1202023https://github.com/FRRouting/frr/commit/6d58272b4cf96f0daa846210dd2104877900f921https://github.com/FRRouting/frr/commit/ff6db1027f8f36df657ff2e5ea167773752537edhttps://lists.debian.org/debian-lts-announce/2022/11/msg00039.htmlhttps://www.debian.org/security/2023/dsa-5362
2022-09-19
Published