Logo
vulnerabilityCVE-2022-43681
Name
CVE-2022-43681
Source
NVD ( link)Debian ( link)
Description
An out-of-bounds read exists in the BGP daemon of FRRouting FRR through 8.4. When sending a malformed BGP OPEN message that ends with the option length octet (or the option length word, in case of an extended OPEN message), the FRR code reads of out of the bounds of the packet, throwing a SIGABRT signal and exiting. This results in a bgpd daemon restart, causing a Denial-of-Service condition.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
frr
Patched

Vulnerability Rating#


6.5
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
10.3
Not Affected
buildroot
master
10.5.4
Not Affected
openwrt
master
10.6.1-r1
Not Affected
yocto
master
10.6.1
Not Affected
yocto
scarthgap
9.1.3
Not Affected

Resolved with patches#


frr (yocto:kirkstone)

#
Title
Author
Resolve
1
bgpd: Ensure that bgp open message stream has enough data to
Donald Sharp <sharpd@nvidia.com>
CVE-2022-43681