CVE-2022-37032: Critical severity frrouting bgpd vulnerability
Published Sep 19, 2022
·Updated
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgpcapabilitymsgparse in bgpd/bgppacket.c.
Affected Software
4 affected componentsFixes available
debian/frr
7.5.1-1.1+deb11u27.5.1-1.1+deb11u48.4.4-1.1~deb12u110.2.1-2
Frrouting FRRouting<8.4
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Sep 19, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Sep 30, 2022
Data Sourced
02:51 PM
SeverityAffected Software
Jun 5, 2024
Data Sourced
via Launchpad·05:52 PM
Description
Sep 21, 2024
Data Sourced
via Ubuntu·06:08 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-37032?
CVE-2022-37032 is an out-of-bounds read vulnerability in the BGP daemon of FRRouting FRR before version 8.4.
2
How does CVE-2022-37032 impact FRRouting and Debian Linux?
CVE-2022-37032 may lead to a segmentation fault and denial of service in FRRouting versions before 8.4 and affects Debian Linux versions 10.0 and 11.0.
3
What is the severity of CVE-2022-37032?
CVE-2022-37032 has a severity rating of 9.1 (critical).
4
How can I fix CVE-2022-37032 in FRRouting?
To fix CVE-2022-37032 in FRRouting, upgrade to version 8.4 or later.
5
How can I fix CVE-2022-37032 in Debian Linux?
To fix CVE-2022-37032 in Debian Linux, update the frr package to one of the following versions: 7.5.1-1.1+deb10u1, 7.5.1-1.1+deb11u2, 8.4.4-1.1~deb12u1, or 8.4.4-1.1.