Unrated severityNVD Advisory· Published Aug 2, 2022· Updated Nov 4, 2025
CVE-2022-37035
CVE-2022-37035
Description
An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.
Affected products
6- FRR/FRRoutingdescription
- osv-coords5 versionspkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/frr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4
< 7.4-150300.4.10.1+ 4 more
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 8.4-1.1
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 7.4-150300.4.10.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.