CVE-2022-37035: Use After Free
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgpnotifysendwithdata() and bgpprocesspacket() in bgppacket.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37035?
The severity of CVE-2022-37035 is high (8.1).
What is the affected software for CVE-2022-37035?
The affected software for CVE-2022-37035 includes FRRouting (FRR) version 8.3.
How can CVE-2022-37035 be exploited?
CVE-2022-37035 can be exploited by sending crafted BGP packets, which may lead to Remote Code Execution or Information Disclosure.
Is there a fix for CVE-2022-37035 available?
Yes, a fix for CVE-2022-37035 is available in FRRouting version 8.4.4-1.1 or later.
Where can I find more information about CVE-2022-37035?
More information about CVE-2022-37035 can be found in the references provided: [link1], [link2], [link3].