Back to Database
Status published
Critical
CVE-2022-37032
An out-of-bounds read in the BGP daemon of FRRouting FRR...
Vulnerability Description
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-37032
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/FRRouting/frr/commit/ff6db1027f8f36df657ff2e5ea167773752537ed
- https://github.com/FRRouting/frr/commit/6d58272b4cf96f0daa846210dd2104877900f921
- https://bugzilla.suse.com/show_bug.cgi?id=1202023
- https://lists.debian.org/debian-lts-announce/2022/11/msg00039.html
- https://www.debian.org/security/2023/dsa-5362
More from frrouting
View All →CVE-2022-43681
An out-of-bounds read exists in the BGP daemon of FRRouting...
Medium
6.5
CVE-2022-40318
An issue was discovered in bgpd in FRRouting (FRR) through...
Medium
6.5
CVE-2022-40302
An issue was discovered in bgpd in FRRouting (FRR) through...
Unknown
0
CVE-2022-37035
An issue was discovered in bgpd in FRRouting (FRR) 8.3....
High
8.1
CVE-2022-36440
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in...
High
7.5
Affected Vendor
frrouting
View all reports →Affected Software
frrouting, debian linux
Vulnerable Versions:
0, 10.0, 11.0
Timeline
Official Publish:
September 19th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.