← Back to CVE Index
CVE-2022-26129
Disclosed 2022-03-03
Description
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Severity & CVSS Score
7.8
HIGH
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer |
Affected FRR Versions
- through 8.1.0
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/issues/10503 | GitHub |
| https://lists.debian.org/debian-lts-announce/2024/04/msg00019.html | Debian |
Git Fixes
Raw Data
- CVE-2022-26129.cve.json — CVE record (JSON)
- CVE-2022-26129.frr.json — FRR-specific data (JSON)