← Vulnerability feed

Vulnerability record · CVE-2022-37035 · published 2 August 2022

CVE-2022-37035: Frrouting race condition vulnerability

Frrouting · Frrouting

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

8.1 CVSS 3.1 High EPSS 2.6% · top 15.4% CWE-362 · Race condition
8.1CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible use-after-free due to a race condition. This could lead to Remote Code Execution or Information Disclosure by sending crafted BGP packets. User interaction is not needed for exploitation.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-37035 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38406Frrouting vulnerabilitybgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."EPSS 0.94%9.8CVE-2023-41361Frrouting classic buffer overflow vulnerabilityAn issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.EPSS 0.90%9.1CVE-2023-41359Frrouting out-of-bounds read vulnerabilityAn issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no ch…EPSS 1.2%9.1CVE-2023-41360Frrouting out-of-bounds read vulnerabilityAn issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.EPSS 1.2%9.1CVE-2022-37032Frrouting out-of-bounds read vulnerabilityAn out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi…EPSS 2.2%7.8CVE-2022-26125Frrouting memory buffer overflow vulnerabilityBuffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.EPSS 1.0%7.8CVE-2022-26126Frrouting memory buffer overflow vulnerabilityBuffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notific…EPSS 1.1%7.8CVE-2022-26127Frrouting memory buffer overflow vulnerabilityA buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin functi…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2022-37035), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.