๐Ÿ” CVE Alert

CVE-2022-42917

MEDIUM 6.7
CVSS Score
6.7
EPSS Score
0.0%
EPSS Percentile
0th

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.

CWE CWE-367
Vendor frrouting
Product frrouting
Published Sep 13, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for frrouting frrouting

Be the first to know when new medium vulnerabilities affecting frrouting frrouting are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

FRRouting / FRRouting
0 < 4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=1204124 frrouting.org: https://frrouting.org/security/cve-2022-42917/ github.com: https://github.com/FRRouting/frr/commit/972cdc560e339d70c0ee5fb70ec636ab78f00bca github.com: https://github.com/FRRouting/frr/compare/frr-8.4...frr-8.5