Skip to content

Fix CVE-2022-37032 on FRR submodule#12435

Merged
yxieca merged 4 commits intosonic-net:masterfrom
DavidZagury:master-frr-cve-updatge
Oct 26, 2022
Merged

Fix CVE-2022-37032 on FRR submodule#12435
yxieca merged 4 commits intosonic-net:masterfrom
DavidZagury:master-frr-cve-updatge

Conversation

@DavidZagury
Copy link
Contributor

Patch was cherry picked from FRRouting/frr repo - d8d77d3733bc299ed5dd7b44c4d464ba2bfed288

This patch should be removed once we upgrade to newer version of FRR that will already includes this fix.

Why I did it

To Fix CVE-2022-37032 on FRR submodule

How I did it

Created a patch from the fixed PR of the FRRouting community - FRRouting/frr@d8d77d3

How to verify it

Compile the FRR.

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205

Description for the changelog

Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU.

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

Patch was cherry picked from FRRouting/frr repo - d8d77d3733bc299ed5dd7b44c4d464ba2bfed288
@liat-grozovik
Copy link
Collaborator

@prsunny , @dgsudharsan appreciate your approval for the change. If someone else needed please add him.
this must go into 202205 as FRR 8.2 was first introduced in.

@prsunny prsunny requested a review from yxieca October 18, 2022 20:48
@dgsudharsan
Copy link
Collaborator

@DavidZagury Can you please change the version number of your patch. I added another patch with same number which just got merged #12453

Patch was cherry picked from FRRouting/frr repo - d8d77d3733bc299ed5dd7b44c4d464ba2bfed288
# Conflicts:
#	src/sonic-frr/patch/series
@DavidZagury
Copy link
Contributor Author

DavidZagury commented Oct 20, 2022

@DavidZagury Can you please change the version number of your patch. I added another patch with same number which just got merged #12453

@dgsudharsan Done

@liat-grozovik
Copy link
Collaborator

@yxieca kindly reminder to review. this should go to 202205

From d8d77d3733bc299ed5dd7b44c4d464ba2bfed288 Mon Sep 17 00:00:00 2001
From: Donald Sharp <sharpd@nvidia.com>
Date: Wed, 20 Jul 2022 16:43:17 -0400
Subject: [PATCH 1/3] ospfclient: Ensure ospf_apiclient_lsa_originate cannot
Copy link
Collaborator

@qiluo-msft qiluo-msft Oct 26, 2022

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PATCH 1/3

I see "PATCH 1/3" is backport of frr upstream commit. How about others? Could you explain 2/3 and 3/3 in PR description?

I see all 3 parts in the PR link https://github.com/FRRouting/frr/pull/12086/files

@yxieca yxieca merged commit 558c904 into sonic-net:master Oct 26, 2022
yxieca pushed a commit that referenced this pull request Oct 27, 2022
* Fix CVE-2022-37032 on FRR submodule

Patch was cherry picked from FRRouting/frr repo - d8d77d3733bc299ed5dd7b44c4d464ba2bfed288

* Fix CVE-2022-37032 on FRR submodule

Patch was cherry picked from FRRouting/frr repo - d8d77d3733bc299ed5dd7b44c4d464ba2bfed288

* Update patch version number
@DavidZagury DavidZagury deleted the master-frr-cve-updatge branch December 19, 2022 14:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants