Buffer Overflow Vulnerability in FRRouting Product by FRRouting
CVE-2022-26127

7.8HIGH

Key Information:

Vendor

Frrouting

Status
Vendor
CVE Published:
3 March 2022

What is CVE-2022-26127?

A buffer overflow issue has been identified in the FRRouting software, present in versions up to 8.1.0. This vulnerability arises from the lack of a proper check on the input packet length within the babel_packet_examin function located in babeld/message.c. Exploitation of this flaw may lead to unforeseen behavior of the software, potentially allowing an attacker to disrupt services or gain unauthorized access to critical components within network infrastructures.

Affected Version(s)

FRRouting through 8.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.