CVE-2022-42917

NameCVE-2022-42917
DescriptionIn FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
frr (PTS)bookworm, bookworm (security)8.4.4-1.1~deb12u2fixed
trixie (security), trixie10.3-3+deb13u1fixed
forky, sid10.7.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
frrsource(unstable)8.4.1-1

Notes

https://bugzilla.suse.com/show_bug.cgi?id=1204124
https://github.com/FRRouting/frr/commit/972cdc560e339d70c0ee5fb70ec636ab78f00bca (frr-8.4-rc)

Search for package or bug name: Reporting problems