CVE-2025-61099

EUVD-2025-36325
FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
frroutingfrrouting
2.0 ≤
𝑥
≤ 10.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
frr
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
10.6.1-1
fixed
sid
10.6.1-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
frr
focal
ignored
jammy
Fixed 8.1-1ubuntu1.14
released
noble
Fixed 8.4.4-1.1ubuntu6.5
released
plucky
ignored
questing
Fixed 10.4.1-3ubuntu1.1
released
resolute
Fixed 10.5.1-1ubuntu2
released
quagga
bionic
needed
focal
needed
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
frr
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
frr-devel
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrr0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrr_pb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrcares0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrfpm_pb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrospfapiclient0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrsnmp0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrzmq0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libmgmt_be_nb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libmlag_pb0
suse enterprise sap 15 SP7
8.5.6-150500.4.36.1
fixed
suse enterprise server 15 SP7
8.5.6-150500.4.36.1
fixed