← Back to CVE Index
CVE-2022-40302
Disclosed 2023-05-03
Description
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case.
Severity & CVSS Score
6.5
MEDIUM
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-125 | Out-of-bounds Read |
Affected FRR Versions
- < 8.4
Versions prior to 7.5 are end-of-life and no longer receive security updates.
References
Git Fixes
- 3e46b43e3788f0f87bae56a86b54d412b4710286
- e4b3afa0993681ca953bf038374f0a62112ab801
- 02a0e45f66160f571196a105b217e1bb84d1a835
Raw Data
- CVE-2022-40302.cve.json — CVE record (JSON)
- CVE-2022-40302.frr.json — FRR-specific data (JSON)