CVE-2022-26127: Buffer Overflow
Published Mar 3, 2022
·Updated
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babelpacketexamin function in babeld/message.c.
Affected Software
2 affected componentsFixes available
Frrouting FRRouting<=8.1
debian/frr<=7.5.1-1.1+deb11u2
7.5.1-1.1+deb11u48.4.4-1.1~deb12u110.2.1-2
Remediation
Event History
Mar 3, 2022
CVE Published
via MITRE·05:21 PM
Data Sourced
via MITRE·05:21 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 21, 2024
Data Sourced
via Ubuntu·06:08 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-26127?
CVE-2022-26127 is a buffer overflow vulnerability in FRRouting through version 8.1.0.
2
What is the severity of CVE-2022-26127?
CVE-2022-26127 has a severity rating of 7.8 (high).
3
How does CVE-2022-26127 work?
CVE-2022-26127 occurs due to a missing check on the input packet length in the babel_packet_examin function in babeld/message.c.
4
Which software versions are affected by CVE-2022-26127?
FRRouting versions up to and including 8.1.0 are affected by CVE-2022-26127.
5
How can I fix CVE-2022-26127?
To fix CVE-2022-26127, update FRRouting to version 8.4.4-1.1~deb12u1 or later.