Search CVE reports


Toggle filters

41 – 49 of 49 results


CVE-2022-36440

Medium priority
Not affected

A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages

CVE-2022-37032

Medium priority

Some fixes available 11 of 13

An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Fixed Not in release
quagga Not in release Not in release Not in release Fixed Vulnerable
Show less packages

CVE-2022-37035

Medium priority
Fixed

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Not in release
Show less packages

CVE-2022-26129

Medium priority

Some fixes available 8 of 9

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed
Show less packages

CVE-2022-26128

Medium priority

Some fixes available 8 of 9

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed
Show less packages

CVE-2022-26127

Medium priority

Some fixes available 8 of 9

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed
Show less packages

CVE-2022-26126

Medium priority

Some fixes available 8 of 9

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed
Show less packages

CVE-2022-26125

Medium priority

Some fixes available 5 of 6

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Not affected
Show less packages

CVE-2020-12831

Low priority
Ignored

An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empty config file with world-readable default permissions, leading to a possible...

1 affected package

frr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Not affected Not in release
Show less packages