CVE-2022-40318: Medium severity frrouting bgpd vulnerability
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case. NOTE: this behavior occurs in bgpopenoptionparse in the bgpopen.c file, a different location (with a different attack vector) relative to CVE-2022-40302.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-40318?
The severity of CVE-2022-40318 is medium.
How does CVE-2022-40318 affect FRRouting?
CVE-2022-40318 affects FRRouting through version 8.4.
What is the potential impact of CVE-2022-40318?
CVE-2022-40318 can cause a denial of service by triggering an assertion failure and daemon restart or out-of-bounds read.
How can I fix CVE-2022-40318 in FRRouting?
To fix CVE-2022-40318 in FRRouting, you should update to the latest version available.
Where can I find more information about CVE-2022-40318?
You can find more information about CVE-2022-40318 on the GitHub releases and issues pages for FRRouting.