PT-2022-17688 · Frrouting+5 · Frrouting+5

CVE-2022-26125

·

Published

2022-03-03

·

Updated

2024-09-03

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FRRouting versions through 8.1.0
Description Buffer overflow vulnerabilities exist due to wrong checks on the input packet length in isisd/isis tlvs.c.
Recommendations For versions through 8.1.0, consider updating to a version that includes the necessary checks for input packet length to prevent buffer overflow. As a temporary workaround, consider restricting access to the isisd/isis tlvs.c module to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:8112
ALT-PU-2022-1555
CVE-2022-26125
DLA-3797-1
DLA-3865-1
OPENSUSE-SU-2022:0901-1
OPENSUSE-SU-2022_0901-1
OPENSUSE-SU-2024:11880-1
RHSA-2022:8112
RHSA-2022_8112
RLSA-2022:8112
SUSE-SU-2022:0901-1
SUSE-SU-2022_0901-1

Affected Products

Alt Linux
Almalinux
Frrouting
Red Hat
Rocky Linux
Suse