CVE-2022-37032Out-of-bounds Read in Frrouting

CWE-125Out-of-bounds Read10 documents6 sources
Severity
9.1CRITICALNVD
OSV7.8
EPSS
1.1%
top 21.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateJun 5

Description

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

debiandebian/frr< frr 8.4.1-1 (bookworm)

Also affects: Debian Linux 10.0, 11.0

Patches

🔴Vulnerability Details

4
OSV
frr vulnerabilities2024-06-05
OSV
frr vulnerabilities2022-10-18
GHSA
GHSA-mxrw-2vpr-fpwr: An out-of-bounds read in the BGP daemon of FRRouting FRR before 82022-09-20
OSV
CVE-2022-37032: An out-of-bounds read in the BGP daemon of FRRouting FRR before 82022-09-19

📋Vendor Advisories

5
Ubuntu
FRR vulnerabilities2024-06-05
Ubuntu
Quagga vulnerabilities2023-11-15
Ubuntu
FRR vulnerabilities2022-10-18
Red Hat
frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service2022-09-20
Debian
CVE-2022-37032: frr - An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to ...2022