An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade frr | Apr 29, 2024 | Aug 2, 2022 |
| Suse | — | Upgrade libfrr0Upgrade frr-develUpgrade libfrrcares0Upgrade libfrrzmq0Upgrade libmlag_pb0Upgrade libfrr_pb0Upgrade libfrrfpm_pb0Upgrade libfrrospfapiclient0Upgrade frrUpgrade libfrrsnmp0Upgrade libfrrgrpc_pb0 | Nov 21, 2022 | Aug 2, 2022 |
| Ubuntu | — | Upgrade frrUpgrade frr (Ubuntu Pro) | Oct 19, 2022 | Aug 2, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub