Unrated severityNVD Advisory· Published Apr 3, 2023· Updated Aug 3, 2024
CVE-2022-36440
CVE-2022-36440
Description
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Affected products
3- Frrouting/frr-bgpddescription
- osv-coords2 versions
< 8.3.1-11.el9_3.alma.1+ 1 more
- (no CPE)range: < 8.3.1-11.el9_3.alma.1
- (no CPE)range: < 8.3.1-11.el9_3.alma.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HU4PKLUVB5CTMOVQ2GV33TNUNMJCBGD/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBXEXL2ZQBWCBLNUP6P67FHECXQWSK3L/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GM66PNHGCXZU66LQCTP2FSJLFF6CVMSI/mitrevendor-advisory
- www.debian.org/security/2023/dsa-5495mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlmitremailing-list
- github.com/spwpun/pocs/blob/main/frr-bgpd.mdmitre
News mentions
0No linked articles in our index yet.