Your submission was sent successfully! Close

USN-5685-1: FRR vulnerabilities

18 October 2022

Several security issues were fixed in FRR.

Releases

Packages

  • frr - FRRouting suite of internet protocols

Details

It was discovered that FRR incorrectly handled parsing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. (CVE-2022-37032)

It was discovered that FRR incorrectly handled processing certain BGP
messages. A remote attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service, obtain sensitive information,
or execute arbitrary code. (CVE-2022-37035)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 22.04

In general, a standard system update will make all the necessary changes.