Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10 Buster DLA-3797-1 Critical: frr Buffer Overflows

debian lts
Calendar Grey April 28, 2024
Dist Debian Esm H88
Debian LTS DLA-3800-2 releases for netfilter, tackling urgent security flaws and recommending immediate package updates.
Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols

Summary

CVE-2022-26125

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to
wrong checks on the input packet length in isisd/isis_tlvs.c.

CVE-2022-26126

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to
the use of strdup with a non-zero-terminated binary string in
isis_nb_notifications.c.

CVE-2022-26127

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to
missing a check on the input packet length in the babel_packet_examin
function in babeld/message.c.

CVE-2022-26128

A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to
a wrong check on the input packet length in the babel_packet_examin
function in babeld/message.c.

CVE-2022-26129

Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to
wrong checks on the subtlv length in the functions, parse_hello_subtlv,
parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

CVE-2022-37035

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: frr
Version: 7.5.1-1.1+deb10u2
CVE ID: CVE-2022-26125 CVE-2022-26126 CVE-2022-26127 CVE-2022-26128
Debian Bug: 1008010 1016978 1055852

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here