PT-2022-17688 · Frrouting+5 · Frrouting+5
Published
2022-03-03
·
Updated
2024-09-03
·
CVE-2022-26125
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FRRouting versions through 8.1.0
Description
Buffer overflow vulnerabilities exist due to wrong checks on the input packet length in isisd/isis tlvs.c.
Recommendations
For versions through 8.1.0, consider updating to a version that includes the necessary checks for input packet length to prevent buffer overflow.
As a temporary workaround, consider restricting access to the isisd/isis tlvs.c module to minimize the risk of exploitation.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Frrouting
Red Hat
Rocky Linux
Suse