Описание
Security update for frr
This update for frr fixes the following issues:
- CVE-2022-26125, CVE-2022-26126: Fixed buffer overflows in unpack_tlv_router_cap() (bsc#1196505, bsc#1196506).
- CVE-2022-26127: Fixed heap buffer overflow in babel_packet_examin() (bsc#1196503).
- CVE-2022-26128: Fixed buffer overflows in babel_packet_examin() (bsc#1196507).
- CVE-2022-26129: Fixed buffer overflows in parse_hello_subtlv(), parse_ihu_subtlv() and parse_update_subtlv() (bsc#1196504).
Список пакетов
SUSE Linux Enterprise Module for Server Applications 15 SP3
Ссылки
- Link for SUSE-SU-2022:0901-1
- E-Mail link for SUSE-SU-2022:0901-1
- SUSE Security Ratings
- SUSE Bug 1180217
- SUSE Bug 1196503
- SUSE Bug 1196504
- SUSE Bug 1196505
- SUSE Bug 1196506
- SUSE Bug 1196507
- SUSE CVE CVE-2022-26125 page
- SUSE CVE CVE-2022-26126 page
- SUSE CVE CVE-2022-26127 page
- SUSE CVE CVE-2022-26128 page
- SUSE CVE CVE-2022-26129 page
Описание
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.
Затронутые продукты
Ссылки
- CVE-2022-26125
- SUSE Bug 1196505
Описание
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
Затронутые продукты
Ссылки
- CVE-2022-26126
- SUSE Bug 1196506
Описание
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.
Затронутые продукты
Ссылки
- CVE-2022-26127
- SUSE Bug 1196503
Описание
A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.
Затронутые продукты
Ссылки
- CVE-2022-26128
- SUSE Bug 1196507
Описание
Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.
Затронутые продукты
Ссылки
- CVE-2022-26129
- SUSE Bug 1196504