Unrated severityNVD Advisory· Published May 3, 2023· Updated Aug 3, 2024
CVE-2022-43681
CVE-2022-43681
Description
An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet, throwing a SIGABRT signal and exiting. This results in a bgpd daemon restart, causing a Denial-of-Service condition.
Affected products
3- osv-coords2 versions
< 8.3.1-11.el9_3.alma.1+ 1 more
- (no CPE)range: < 8.3.1-11.el9_3.alma.1
- (no CPE)range: < 8.3.1-11.el9_3.alma.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.debian.org/security/2023/dsa-5495mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2023/09/msg00020.htmlmitremailing-list
- forescout.commitre
News mentions
0No linked articles in our index yet.