openSUSE-SU-2022:0901-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:0901-1
openSUSE-SU-2022:0901-1
Summary: Security update for frr
Details: This update for frr fixes the following issues: - CVE-2022-26125, CVE-2022-26126: Fixed buffer overflows in unpack_tlv_router_cap() (bsc#1196505, bsc#1196506). - CVE-2022-26127: Fixed heap buffer overflow in babel_packet_examin() (bsc#1196503). - CVE-2022-26128: Fixed buffer overflows in babel_packet_examin() (bsc#1196507). - CVE-2022-26129: Fixed buffer overflows in parse_hello_subtlv(), parse_ihu_subtlv() and parse_update_subtlv() (bsc#1196504).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/IMU2X5TQEN42TVGMLEB32I5WD3N5Z2FU/, https://bugzilla.suse.com/1180217, https://bugzilla.suse.com/1196503, https://bugzilla.suse.com/1196504, https://bugzilla.suse.com/1196505, https://bugzilla.suse.com/1196506, https://bugzilla.suse.com/1196507, https://www.suse.com/security/cve/CVE-2022-26125, https://www.suse.com/security/cve/CVE-2022-26126, https://www.suse.com/security/cve/CVE-2022-26127, https://www.suse.com/security/cve/CVE-2022-26128, https://www.suse.com/security/cve/CVE-2022-26129
Affected packages
Package
Name: frr
Purl: pkg:rpm/opensuse/frr&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
