CVE-2026-37457
EUVD-2026-2670301.05.2026, 18:16
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| frrouting | frrouting | 10.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:10.4.4-1.el10_2 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 8 | 0:7.5.1-24.el8_10 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:10.4.3-3.el9_8 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:8.5.3-13.el9_8 ≤ 𝑥 < * | ADP |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| frr |
| ||||||||||||||||
| frr-devel |
| ||||||||||||||||
| libfrr0 |
| ||||||||||||||||
| libfrr_pb0 |
| ||||||||||||||||
| libfrrcares0 |
| ||||||||||||||||
| libfrrfpm_pb0 |
| ||||||||||||||||
| libfrrgrpc_pb0 |
| ||||||||||||||||
| libfrrospfapiclient0 |
| ||||||||||||||||
| libfrrsnmp0 |
| ||||||||||||||||
| libfrrzmq0 |
| ||||||||||||||||
| libmgmt_be_nb0 |
| ||||||||||||||||
| libmlag_pb0 |
|
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References