-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: frr security, bug fix, and enhancement update
Advisory ID:       RHSA-2022:8112-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2022:8112
Issue date:        2022-11-15
CVE Names:         CVE-2022-26125 
====================================================================
1. Summary:

An update for frr is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64

3. Description:

FRRouting is free software that manages TCP/IP based routing protocols. It
supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and
BFD.

The following packages have been upgraded to a later upstream version: frr
(8.2.2). (BZ#2069563)

Security Fix(es):

* frrouting: overflow bugs in unpack_tlv_router_cap (CVE-2022-26125)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat
Enterprise Linux 9.1 Release Notes linked from the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

2058628 - CVE-2022-26125 frrouting: overflow bugs in unpack_tlv_router_cap
2069563 - [RFE] Rebase frr to more recent version
2081304 - Enhanced TMT testing for centos-stream
2095404 - [RFE] frr use systemd-sysusers
6. Package List:

Red Hat Enterprise Linux AppStream (v. 9):

Source:
frr-8.2.2-4.el9.src.rpm

aarch64:
frr-8.2.2-4.el9.aarch64.rpm
frr-debuginfo-8.2.2-4.el9.aarch64.rpm
frr-debugsource-8.2.2-4.el9.aarch64.rpm

ppc64le:
frr-8.2.2-4.el9.ppc64le.rpm
frr-debuginfo-8.2.2-4.el9.ppc64le.rpm
frr-debugsource-8.2.2-4.el9.ppc64le.rpm

s390x:
frr-8.2.2-4.el9.s390x.rpm
frr-debuginfo-8.2.2-4.el9.s390x.rpm
frr-debugsource-8.2.2-4.el9.s390x.rpm

x86_64:
frr-8.2.2-4.el9.x86_64.rpm
frr-debuginfo-8.2.2-4.el9.x86_64.rpm
frr-debugsource-8.2.2-4.el9.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2022-26125
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBY3OMUNzjgjWX9erEAQjmRQ/8C+N9RcZ/p4xeChDLXCORo6PXc9PHXUar
bO+6ce/DwTmDd9kCw7uqwCsxidxmz//+P3pUoX20y9R5Dwt4pICSjVwE5PlQiK/X
YufPTCZyC39ARiFZUO7iWEYii7EIktd3Uw2Holn3fUbQX+4WjaMSZNeiFG4uvhd4
uLt7tF1JhIJpTRs1cFSMXKpqeuy+c02rl3HOnm7YfuCABhESawzBRVQpS490OA0x
gWg3me0IT3jBQH9zw6y7zBuNFA9XH9122R2i3a+pnB0d2ScFjPYlBzxeoCTdBZxf
it9Pjqhxq4bssINLlSJyY8ZCxrdcuBVJbJsoJIpTskvONmQxm0Jfl1WbbyuaW4J1
8YFKlwFGyNw0YvzFsrdO+LWhCulSE/4o2vixmr3gcR1EHx9TD43OlFwbBhSjvsR/
u5hKKvQbwOSkfmpQu6jsK8IR9oKo7h1W5aolXshCnrp47cJFXU9FEJALWVa49yHm
VUrjibqUTYJkcKEz2wJM7iD+EAIGvEJkwtCRcYKXzEwy1iTReqIhirUsU+xG+Wy4
3osfjYX3ZTnDZC1EhO3drImrtP+CYdKYbd4/z3ZdO42wHh4d0I9G6DFlb37bFqHu
OMmPjuzBtW+rELygJUww71rutWUfsqjzSMLzFLqK2aPc5DoKcAmWoD0/35sxirsX
vLlY8OoHyn8=yO13
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2022-8112:01 Moderate: frr security, bug fix,

An update for frr is now available for Red Hat Enterprise Linux 9

Summary

FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.
The following packages have been upgraded to a later upstream version: frr (8.2.2). (BZ#2069563)
Security Fix(es):
* frrouting: overflow bugs in unpack_tlv_router_cap (CVE-2022-26125)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.1 Release Notes linked from the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2022-26125 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/9.1_release_notes/index

Package List

Red Hat Enterprise Linux AppStream (v. 9):
Source: frr-8.2.2-4.el9.src.rpm
aarch64: frr-8.2.2-4.el9.aarch64.rpm frr-debuginfo-8.2.2-4.el9.aarch64.rpm frr-debugsource-8.2.2-4.el9.aarch64.rpm
ppc64le: frr-8.2.2-4.el9.ppc64le.rpm frr-debuginfo-8.2.2-4.el9.ppc64le.rpm frr-debugsource-8.2.2-4.el9.ppc64le.rpm
s390x: frr-8.2.2-4.el9.s390x.rpm frr-debuginfo-8.2.2-4.el9.s390x.rpm frr-debugsource-8.2.2-4.el9.s390x.rpm
x86_64: frr-8.2.2-4.el9.x86_64.rpm frr-debuginfo-8.2.2-4.el9.x86_64.rpm frr-debugsource-8.2.2-4.el9.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2022:8112-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2022:8112
Issued Date: : 2022-11-15
CVE Names: CVE-2022-26125

Topic

An update for frr is now available for Red Hat Enterprise Linux 9.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64


Bugs Fixed

2058628 - CVE-2022-26125 frrouting: overflow bugs in unpack_tlv_router_cap

2069563 - [RFE] Rebase frr to more recent version

2081304 - Enhanced TMT testing for centos-stream

2095404 - [RFE] frr use systemd-sysusers


Related News