Unrated severityNVD Advisory· Published Mar 3, 2022· Updated Nov 4, 2025
CVE-2022-26126
CVE-2022-26126
Description
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Affected products
4- osv-coords3 versionspkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/frr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
< 7.4-150300.4.3.1+ 2 more
- (no CPE)range: < 7.4-150300.4.3.1
- (no CPE)range: < 8.1-3.1
- (no CPE)range: < 7.4-150300.4.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MIEQNIWUSBQTFR65HM2LLIB7PH27CZUZ/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VTYSAL4QCE4XWMMBKUB7LSLPAFLWUML4/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XUCZR6RYQVZ35BFUV7OLIUEHZW2433I2/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2024/04/msg00019.htmlmitremailing-list
- github.com/FRRouting/frr/issues/10505mitre
News mentions
0No linked articles in our index yet.