{"id":"SUSE-SU-2022:0901-1","summary":"Security update for frr","details":"This update for frr fixes the following issues:\n\n- CVE-2022-26125, CVE-2022-26126: Fixed buffer overflows in unpack_tlv_router_cap() (bsc#1196505, bsc#1196506).\n- CVE-2022-26127: Fixed heap buffer overflow in babel_packet_examin() (bsc#1196503).\n- CVE-2022-26128: Fixed buffer overflows in babel_packet_examin() (bsc#1196507).\n- CVE-2022-26129: Fixed buffer overflows in parse_hello_subtlv(), parse_ihu_subtlv() and parse_update_subtlv() (bsc#1196504).\n","modified":"2026-03-11T07:18:43.907079Z","published":"2022-03-18T11:02:04Z","related":["CVE-2022-26125","CVE-2022-26126","CVE-2022-26127","CVE-2022-26128","CVE-2022-26129"],"upstream":["CVE-2022-26125","CVE-2022-26126","CVE-2022-26127","CVE-2022-26128","CVE-2022-26129"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20220901-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196503"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196504"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196505"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26125"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26126"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26128"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26129"}],"affected":[{"package":{"name":"frr","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP3","purl":"pkg:rpm/suse/frr&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.4-150300.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"libfrrcares0":"7.4-150300.4.3.1","libfrrgrpc_pb0":"7.4-150300.4.3.1","libfrrospfapiclient0":"7.4-150300.4.3.1","libmlag_pb0":"7.4-150300.4.3.1","frr-devel":"7.4-150300.4.3.1","frr":"7.4-150300.4.3.1","libfrr_pb0":"7.4-150300.4.3.1","libfrrfpm_pb0":"7.4-150300.4.3.1","libfrrsnmp0":"7.4-150300.4.3.1","libfrrzmq0":"7.4-150300.4.3.1","libfrr0":"7.4-150300.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0901-1.json"}}],"schema_version":"1.7.5"}