Vulnerability Details CVE-2022-40302
An issue was discovered in bgpd in FRRouting (FRR) through 8.4. By crafting a BGP OPEN message with an option of type 0xff (Extended Length from RFC 9072), attackers may cause a denial of service (assertion failure and daemon restart, or out-of-bounds read). This is possible because of inconsistent boundary checks that do not account for reading 3 bytes (instead of 2) in this 0xff case.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2022-40302
-
cpe:2.3:a:frrouting:frrouting:-
-
cpe:2.3:a:frrouting:frrouting:2.0
-
cpe:2.3:a:frrouting:frrouting:2.0.1
-
cpe:2.3:a:frrouting:frrouting:2.0.2
-
cpe:2.3:a:frrouting:frrouting:3.0
-
cpe:2.3:a:frrouting:frrouting:3.0.1
-
cpe:2.3:a:frrouting:frrouting:3.0.2
-
cpe:2.3:a:frrouting:frrouting:3.0.3
-
cpe:2.3:a:frrouting:frrouting:3.0.4
-
cpe:2.3:a:frrouting:frrouting:4.0
-
cpe:2.3:a:frrouting:frrouting:4.0.1
-
cpe:2.3:a:frrouting:frrouting:5.0
-
cpe:2.3:a:frrouting:frrouting:5.0.1
-
cpe:2.3:a:frrouting:frrouting:5.0.2
-
cpe:2.3:a:frrouting:frrouting:6.0
-
cpe:2.3:a:frrouting:frrouting:6.0.1
-
cpe:2.3:a:frrouting:frrouting:6.0.2
-
cpe:2.3:a:frrouting:frrouting:6.0.3
-
cpe:2.3:a:frrouting:frrouting:7.0
-
cpe:2.3:a:frrouting:frrouting:7.0.1
-
cpe:2.3:a:frrouting:frrouting:7.1
-
cpe:2.3:a:frrouting:frrouting:7.2
-
cpe:2.3:a:frrouting:frrouting:7.2.1
-
cpe:2.3:a:frrouting:frrouting:7.3
-
cpe:2.3:a:frrouting:frrouting:7.3.1
-
cpe:2.3:a:frrouting:frrouting:7.4
-
cpe:2.3:a:frrouting:frrouting:7.5
-
cpe:2.3:a:frrouting:frrouting:7.5.1
-
cpe:2.3:a:frrouting:frrouting:8.0
-
cpe:2.3:a:frrouting:frrouting:8.0.1
-
cpe:2.3:a:frrouting:frrouting:8.1
-
cpe:2.3:a:frrouting:frrouting:8.2
-
cpe:2.3:a:frrouting:frrouting:8.2.1
-
cpe:2.3:a:frrouting:frrouting:8.2.2
-
cpe:2.3:a:frrouting:frrouting:8.3
-
cpe:2.3:a:frrouting:frrouting:8.3.1
-
cpe:2.3:a:frrouting:frrouting:8.3.2
-
cpe:2.3:a:frrouting:frrouting:8.4
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:11.0
-
cpe:2.3:o:debian:debian_linux:12.0