CVE-2022-36440: High severity frrouting bgpd vulnerability
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peekforas4capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36440?
CVE-2022-36440 is a vulnerability found in Frrouting frr-bgpd 8.3.0 that allows attackers to construct malicious BGP open packets, resulting in a denial-of-service (DoS) attack.
What is the severity of CVE-2022-36440?
The severity of CVE-2022-36440 is high, with a severity value of 7.5.
How does CVE-2022-36440 affect Frrouting?
CVE-2022-36440 affects Frrouting frr-bgpd 8.3.0, allowing attackers to exploit the vulnerability and cause a DoS attack.
How can I fix CVE-2022-36440?
To fix CVE-2022-36440, it is recommended to update Frrouting to version 8.4.4-1.1 or later.
Where can I find more information about CVE-2022-36440?
More information about CVE-2022-36440 can be found in the following references: [Reference 1](https://github.com/FRRouting/frr/issues/13202), [Reference 2](https://github.com/FRRouting/frrcommit/3e46b43e3788f0f87bae56a86b54d412b4710286), [Reference 3](https://github.com/spwpun/pocs/blob/main/frr-bgpd.md).