UBUNTU-CVE-2022-37035
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-37035
UBUNTU-CVE-2022-37035
Summary:
Details: An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.
References: https://ubuntu.com/security/CVE-2022-37035, https://docs.google.com/document/d/1TqYEcZbFeDTMKe2N4XRFwyAjw_mynIHfvzwbx1fmJj8/edit?usp=sharing, https://ubuntu.com/security/notices/USN-5685-1, https://www.cve.org/CVERecord?id=CVE-2022-37035, https://ubuntu.com/security/notices/USN-6807-1
Affected packages
Package
Name: frr
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-apps/focal
Affected ranges
Type: ECOSYSTEM
Events:
