CVE-2022-40318
- EPSS 1.98%
- Veröffentlicht 03.05.2023 12:16:27
- Zuletzt bearbeitet 21.11.2024 07:21:18
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bound...
CVE-2022-40302
- EPSS 1.98%
- Veröffentlicht 03.05.2023 12:16:27
- Zuletzt bearbeitet 30.01.2025 17:15:11
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bound...
CVE-2022-36440
- EPSS 1.64%
- Veröffentlicht 03.04.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 07:13:00
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
CVE-2022-37032
- EPSS 1.69%
- Veröffentlicht 19.09.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 07:14:19
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
CVE-2022-37035
- EPSS 2.41%
- Veröffentlicht 02.08.2022 23:15:18
- Zuletzt bearbeitet 04.11.2025 16:15:50
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Discl...
CVE-2022-26129
- EPSS 1.01%
- Veröffentlicht 03.03.2022 18:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:48
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
CVE-2022-26128
- EPSS 0.98%
- Veröffentlicht 03.03.2022 18:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:48
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.
CVE-2022-26127
- EPSS 1.01%
- Veröffentlicht 03.03.2022 18:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:48
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.
CVE-2022-26126
- EPSS 1.09%
- Veröffentlicht 03.03.2022 18:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:48
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
CVE-2022-26125
- EPSS 1.01%
- Veröffentlicht 03.03.2022 18:15:08
- Zuletzt bearbeitet 04.11.2025 16:15:47
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.