summaryrefslogtreecommitdiffstats
path: root/meta-oe
diff options
context:
space:
mode:
authorYi Zhao <yi.zhao@windriver.com>2022-09-24 15:39:57 +0800
committerArmin Kuster <akuster808@gmail.com>2022-09-25 11:00:46 -0400
commitfc9c8a3332e606aad4b398a77085208f61af6f44 (patch)
tree578749b5e5d35df9a41ce9a678e339f4cd9a3113 /meta-oe
parentc5b5f631fc485e91f67827c536c06215a803d7cc (diff)
downloadmeta-openembedded-fc9c8a3332e606aad4b398a77085208f61af6f44.tar.gz
frr: Security fix CVE-2022-37035
CVE-2022-37035: An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation. Reference: https://nvd.nist.gov/vuln/detail/CVE-2022-37035 Patch from: https://github.com/FRRouting/frr/commit/71ca5b09bc71e8cbe38177cf41e83fe164e52eee Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Diffstat (limited to 'meta-oe')
0 files changed, 0 insertions, 0 deletions