Skip to content

[FRR][CVE] Add FRR patches to fix CVEs: CVE-2022-43681 CVE-2022-40318…#15262

Merged
qiluo-msft merged 1 commit intosonic-net:masterfrom
DavidZagury:master_frr_cves_2305
Jun 5, 2023
Merged

[FRR][CVE] Add FRR patches to fix CVEs: CVE-2022-43681 CVE-2022-40318…#15262
qiluo-msft merged 1 commit intosonic-net:masterfrom
DavidZagury:master_frr_cves_2305

Conversation

@DavidZagury
Copy link
Contributor

CVE-2022-40302

Add patches from PRs
FRRouting/frr#12043
FRRouting/frr#12247

Why I did it

To fix CVEs found in FRR 8.2

Work item tracking
  • Microsoft ADO (number only):

How I did it

Take commit from the FRR repo and created a patch from them

How to verify it

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

Copy link
Contributor

@maipbui maipbui left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@DavidZagury
Copy link
Contributor Author

@StormLiangMS there is a different PR for 202211 and 202205, please don't merge it to these branches
#15263

@qiluo-msft qiluo-msft merged commit 2905107 into sonic-net:master Jun 5, 2023
sonic-otn pushed a commit to sonic-otn/sonic-buildimage that referenced this pull request Sep 20, 2023
…VE-2022-40302 (sonic-net#15262)

Add patches from PRs
FRRouting/frr#12043
FRRouting/frr#12247

#### Why I did it
To fix CVEs found in FRR 8.2

#### How I did it
Take commit from  the FRR repo and created a patch from them
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants