First published: Mon Sep 19 2022(Updated: )
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Frrouting Frrouting | <8.4 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
debian/frr | 7.5.1-1.1+deb11u2 7.5.1-1.1+deb11u3 8.4.4-1.1~deb12u1 10.1.1-0.1 10.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37032 is an out-of-bounds read vulnerability in the BGP daemon of FRRouting FRR before version 8.4.
CVE-2022-37032 may lead to a segmentation fault and denial of service in FRRouting versions before 8.4 and affects Debian Linux versions 10.0 and 11.0.
CVE-2022-37032 has a severity rating of 9.1 (critical).
To fix CVE-2022-37032 in FRRouting, upgrade to version 8.4 or later.
To fix CVE-2022-37032 in Debian Linux, update the frr package to one of the following versions: 7.5.1-1.1+deb10u1, 7.5.1-1.1+deb11u2, 8.4.4-1.1~deb12u1, or 8.4.4-1.1.