First published: Mon Apr 03 2023(Updated: )
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/frr | <=6.0.2-2+deb10u1 | 7.5.1-1.1+deb10u1 7.5.1-1.1+deb11u2 8.4.4-1.1~deb12u1 8.4.4-1.1 |
Frrouting Frrouting | =8.3 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36440 is a vulnerability found in Frrouting frr-bgpd 8.3.0 that allows attackers to construct malicious BGP open packets, resulting in a denial-of-service (DoS) attack.
The severity of CVE-2022-36440 is high, with a severity value of 7.5.
CVE-2022-36440 affects Frrouting frr-bgpd 8.3.0, allowing attackers to exploit the vulnerability and cause a DoS attack.
To fix CVE-2022-36440, it is recommended to update Frrouting to version 8.4.4-1.1 or later.
More information about CVE-2022-36440 can be found in the following references: [Reference 1](https://github.com/FRRouting/frr/issues/13202), [Reference 2](https://github.com/FRRouting/frrcommit/3e46b43e3788f0f87bae56a86b54d412b4710286), [Reference 3](https://github.com/spwpun/pocs/blob/main/frr-bgpd.md).