← Back to CVE Index
CVE-2022-36440
Disclosed 2023-04-03
Description
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Severity
High
Affected FRR Versions
- < 8.4
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/3e46b43e3788f0f87bae56a86b54d412b4710286 | GitHub |
Git Fixes
- 3e46b43e3788f0f87bae56a86b54d412b4710286
- e4b3afa0993681ca953bf038374f0a62112ab801
- 02a0e45f66160f571196a105b217e1bb84d1a835
Raw Data
- CVE-2022-36440.cve.json — CVE record (JSON)
- CVE-2022-36440.frr.json — FRR-specific data (JSON)