frr-7.5.1-7.el8

エラータID: AXSA:2023-5825:03

Release date: 
Monday, June 5, 2023 - 12:18
Subject: 
frr-7.5.1-7.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.

Security Fix(es):

* frr: out-of-bounds read in the BGP daemon may lead to information disclosure or denial of service (CVE-2022-37032)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2022-37032
An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. frr-7.5.1-7.el8.src.rpm
    MD5: 75f9dfd9c43c61dbf14b20a8d8c0691b
    SHA-256: 6663e5ee56b04ed2094aa6588231fcb9157d7da7509ca55034b6262ebd279d78
    Size: 6.42 MB

Asianux Server 8 for x86_64
  1. frr-7.5.1-7.el8.x86_64.rpm
    MD5: 253286cf3cb1afa189f53b460d81eaf5
    SHA-256: 0bada769884a93e207e0952597513a68ef15db404a0414ff3b3f17139d275b6f
    Size: 3.15 MB
  2. frr-selinux-7.5.1-7.el8.noarch.rpm
    MD5: bba5e0e5c71f4694ee22f561431008fa
    SHA-256: 91b6a7b511f122651fe3fb623b148e65a622585c557a94e2604e1cf37730b931
    Size: 24.22 kB