Aller au contenu

Fiche vulnérabilité

CVE-2022-37035 : faille élevée frrouting frrouting (CVSS 8.1)

Description

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

En bref

Sévérité
Élevée (CVSS 8.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
2 août 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • frrouting frrouting

Références

Rechercher une autre vulnérabilité dans la base CVE