Impact
The FRRouting service user can elevate its privileges to root by exploiting a TOCTOU race condition in the configuration directory (/etc/frr). By monitoring when configuration files are created and replacing them with symlinks, an attacker can change the ownership of arbitrary files, allowing root access. This flaw stems from a race between touch and chown operations, as indicated by the CWE-367 classification.
Affected Systems
The vulnerability affects the FRRouting FRRouting distribution prior to version 8.5. Any installation using an older FRRouting release that runs the service user frr and writes to /etc/frr is susceptible.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the attack vector is local: an actor with write access to the /etc/frr directory (typically the frr service user) can trigger the race and gain root privileges. The likelihood of exploitation depends on the system’s configuration and the attacker’s ability to write to the configuration files; it remains a significant threat for environments where FRRouting runs with elevated privileges.
OpenCVE Enrichment