CVE-2025-61105

EUVD-2025-36350
FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
frroutingfrrouting
4.0 ≤
𝑥
≤ 10.4.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
frr
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
10.6.1-1
fixed
sid
10.6.1-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
quagga
bionic
needed
focal
needed
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needed
frr
focal
needed
jammy
Fixed 8.1-1ubuntu1.14
released
noble
Fixed 8.4.4-1.1ubuntu6.5
released
plucky
ignored
questing
Fixed 10.4.1-3ubuntu1.1
released
resolute
Fixed 10.5.1-1ubuntu2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
frr
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
frr-devel
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrr0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrr_pb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrcares0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrfpm_pb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrospfapiclient0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrsnmp0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libfrrzmq0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libmgmt_be_nb0
suse enterprise sap 15 SP7
10.2.1-150700.3.5.1
fixed
suse enterprise server 15 SP7
10.2.1-150700.3.5.1
fixed
libmlag_pb0
suse enterprise sap 15 SP7
8.5.6-150500.4.36.1
fixed
suse enterprise server 15 SP7
8.5.6-150500.4.36.1
fixed