7.5
CVSSv3

CVE-2022-36440

Published: 03/04/2023 Updated: 01/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.

Vulnerable Product Search on Vulmon Subscribe to Product

frrouting frrouting 8.3

fedoraproject fedora 36

fedoraproject fedora 37

fedoraproject fedora 38

debian debian linux 10.0

debian debian linux 11.0

debian debian linux 12.0

Vendor Advisories

Synopsis Moderate: frr security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for frr is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having ...
Multiple vulnerabilities were discovered in frr, the FRRouting suite of internet protocols, while processing malformed requests and packets the BGP daemon may have reachable assertions, NULL pointer dereference, out-of-bounds memory access, which may lead to denial of service attack For the oldstable distribution (bullseye), these problems have be ...
DescriptionThe MITRE CVE dictionary describes this issue as: A reachable assertion was found in Frrouting frr-bgpd 830 in the peek_for_as4_capability function Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS ...