Medium severity6.7NVD Advisory· Published Sep 14, 2026
CVE-2022-42917
CVE-2022-42917
Description
In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.
Affected products
6- osv-coords5 versionspkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/frr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4
< 7.4-150300.4.10.1+ 4 more
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 8.4-1.1
- (no CPE)range: < 7.4-150300.4.10.1
- (no CPE)range: < 7.4-150300.4.10.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.