Description
In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.
Published: 2026-09-13
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The FRRouting service user can elevate its privileges to root by exploiting a TOCTOU race condition in the configuration directory (/etc/frr). By monitoring when configuration files are created and replacing them with symlinks, an attacker can change the ownership of arbitrary files, allowing root access. This flaw stems from a race between touch and chown operations, as indicated by the CWE-367 classification.

Affected Systems

The vulnerability affects the FRRouting FRRouting distribution prior to version 8.5. Any installation using an older FRRouting release that runs the service user frr and writes to /etc/frr is susceptible.

Risk and Exploitability

The CVSS score of 6.7 indicates a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local: an actor with write access to the /etc/frr directory (typically the frr service user) can trigger the race and gain root privileges. The likelihood of exploitation depends on the system’s configuration and the attacker’s ability to write to the configuration files; it remains a significant threat for environments where FRRouting runs with elevated privileges.

Generated by OpenCVE AI on September 15, 2026 at 18:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FRRouting to version 8.5 or later to apply the fix that removes the race condition.
  • Ensure the /etc/frr directory and its files are owned by root and are not writable by the frr service user; set permissions to 755 and remove group or user write rights.
  • Remove any symlink support that permits following in the configuration directory, or disable the feature if possible, to prevent malicious file redirection.

Generated by OpenCVE AI on September 15, 2026 at 18:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title frr: FRRouting FRR: Privilege escalation via TOCTOU race condition
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 13 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Frrouting
Frrouting frrouting
Weaknesses CWE-367
CPEs cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*
Vendors & Products Frrouting
Frrouting frrouting
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Sun, 13 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination of touch and chown.
References

Subscriptions

Frrouting Frrouting
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T18:15:19.986Z

Reserved: 2022-10-13T00:00:00.000Z

Link: CVE-2022-42917

cve-icon Vulnrichment

Updated: 2026-09-14T15:03:59.389Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T00:16:55.700

Modified: 2026-09-22T19:56:19.073

Link: CVE-2022-42917

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T00:00:00Z

Links: CVE-2022-42917 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:30:14Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition