← Back to CVE Index
CVE-2022-37032
Disclosed 2022-09-19
Description
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Severity
Critical
Affected FRR Versions
- < 8.4
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/ff6db1027f8f36df657ff2e5ea167773752537ed | GitHub |
Git Fixes
- ff6db1027f8f36df657ff2e5ea167773752537ed
- db057ef0e31ac2c7653e8a9b108c7904a798553b
- 066770ac1c69ee5b484bb82581b22ad0423b004d
- 3c4821679f2362bcd38fcc7803f28a5210441ddb
Raw Data
- CVE-2022-37032.cve.json — CVE record (JSON)
- CVE-2022-37032.frr.json — FRR-specific data (JSON)