CVE-2026-37457

EUVD-2026-26703
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
Affected Products (NVD)
VendorProductVersion
frroutingfrrouting
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
frr
bookworm
vulnerable
bookworm (security)
8.4.4-1.1~deb12u2
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
forky
10.6.1-2
fixed
sid
10.6.1-2
fixed
trixie
vulnerable
trixie (security)
10.3-3+deb13u1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
frr
RHEL 8
0:7.5.1-24.el8_10
fixed
RHEL 9
0:8.5.3-13.el9_8
fixed
frr-selinux
RHEL 8
0:7.5.1-24.el8_10
fixed
RHEL 9
0:8.5.3-13.el9_8
fixed
frr10
RHEL 9
0:10.4.3-3.el9_8
fixed
frr10-selinux
RHEL 9
0:10.4.3-3.el9_8
fixed