PT-2022-17688 · Frrouting+5 · Frrouting+5

Published

2022-03-03

·

Updated

2024-09-03

·

CVE-2022-26125

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FRRouting versions through 8.1.0
Description Buffer overflow vulnerabilities exist due to wrong checks on the input packet length in isisd/isis tlvs.c.
Recommendations For versions through 8.1.0, consider updating to a version that includes the necessary checks for input packet length to prevent buffer overflow. As a temporary workaround, consider restricting access to the isisd/isis tlvs.c module to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2022:8112
ALT-PU-2022-1555
CVE-2022-26125
DLA-3797-1
DLA-3865-1
OPENSUSE-SU-2022:0901-1
OPENSUSE-SU-2022_0901-1
OPENSUSE-SU-2024:11880-1
RHSA-2022:8112
RHSA-2022_8112
RLSA-2022:8112
SUSE-SU-2022:0901-1
SUSE-SU-2022_0901-1

Affected Products

Alt Linux
Almalinux
Frrouting
Red Hat
Rocky Linux
Suse