SUSE-SU-2022:4130-1
Dashboard / Vulnerabilities / SUSE-SU-2022:4130-1
SUSE-SU-2022:4130-1
Summary: Security update for frr
Details: This update for frr fixes the following issues: - CVE-2022-37035: Fixed a possible use-after-free due to a race condition related to bgp_notify_send_with_data() and bgp_process_packet() (bsc#1202085). - CVE-2022-42917: Fixed a privilege escalation from frr to root in frr config creation (bsc#1204124).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20224130-1/, https://bugzilla.suse.com/1202085, https://bugzilla.suse.com/1204124, https://www.suse.com/security/cve/CVE-2022-37035, https://www.suse.com/security/cve/CVE-2022-42917
Affected packages
Package
Name: frr
Purl: pkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
