Buffer Overflow Vulnerability in FRRouting Software
CVE-2022-26129
7.8HIGH
What is CVE-2022-26129?
A buffer overflow vulnerability has been identified in FRRouting software versions up to 8.1.0. This vulnerability arises from inadequate checks on the subtlv length in specific parsing functions: parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv located in babeld/message.c. Exploitation of this vulnerability may allow an attacker to manipulate memory and potentially execute arbitrary code within affected instances.
Affected Version(s)
FRRouting through 8.1.0