Buffer Overflow Vulnerability in FRRouting Product by FRRouting
CVE-2022-26128

7.8HIGH

Key Information:

Vendor

Frrouting

Status
Vendor
CVE Published:
3 March 2022

What is CVE-2022-26128?

A buffer overflow vulnerability was identified in the FRRouting implementation due to improper validation of input packet lengths in the babel_packet_examin function, located in babeld/message.c. This flaw could allow attackers to exploit the vulnerability by crafting malicious packets that, when processed, could lead to execution of arbitrary code or service disruption. Users are encouraged to update to the latest FRRouting version to mitigate potential risks associated with this vulnerability.

Affected Version(s)

FRRouting through 8.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.