VYPR
Vendor

Frrouting

Products
3
CVEs
53
Across products
103
Status
Private

Products

3

Recent CVEs

53
View all 53 CVEs →
  • CVE-2022-37035HigAug 2, 2022
    risk 0.53cvss 8.1epss 0.03

    An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP…

  • CVE-2022-26129HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

  • CVE-2022-26128HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.

  • CVE-2022-26127HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.

  • CVE-2022-26126HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

  • CVE-2022-26125HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

  • CVE-2023-38802HigAug 29, 2023
    risk 0.49cvss 7.5epss 0.02

    FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).

  • CVE-2023-31490HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.02

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

  • CVE-2017-15865HigNov 8, 2017
    risk 0.49cvss 7.5epss 0.02

    bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few…

  • CVE-2026-37460HigJun 3, 2026
    risk 0.42cvss 7.5epss 0.01

    Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

  • CVE-2026-37459HigMay 4, 2026
    risk 0.42cvss 7.5epss 0.01

    An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

  • CVE-2026-37457HigMay 1, 2026
    risk 0.42cvss 7.5epss 0.01

    An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

  • CVE-2024-55553HigJan 6, 2025
    risk 0.42cvss 7.5epss 0.01

    In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An attacker can use this to trigger re-parsing of the RIB for FRR routers using RTR by…

  • CVE-2022-43681MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet,…

  • CVE-2022-40318MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible…

  • CVE-2022-40302MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible…

  • CVE-2022-36440HigApr 3, 2023
    risk 0.42cvss 7.5epss 0.02

    A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.

  • CVE-2019-5892MedJan 10, 2019
    risk 0.42cvss 6.5epss 0.03

    bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x before 6.0.2 (not affecting Cumulus Linux or VyOS), when ENABLE_BGP_VNC is used for Virtual Network Control, allows remote attackers to cause a denial of service…

  • CVE-2022-42917MedSep 14, 2026
    risk 0.37cvss 6.7epss 0.00

    In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU…

  • CVE-2023-31489MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.01

    An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.