CVE-2026-37458

EUVD-2026-26977
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
frroutingfrrouting
10.0 ≤
𝑥
≤ 10.6.0
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
frr
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
frr-devel
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrr0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrr_pb0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrrcares0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrrfpm_pb0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrrospfapiclient0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrrsnmp0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 12 SP5
8.5.7-8.16.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libfrrzmq0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libmgmt_be_nb0
suse enterprise sap 15 SP7
10.2.6-150700.3.10.1
fixed
suse enterprise server 15 SP7
10.2.6-150700.3.10.1
fixed
libmlag_pb0
suse enterprise sap 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise sap 15 SP7
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP5
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP6
8.5.7-150500.4.43.1
fixed
suse enterprise server 15 SP7
8.5.7-150500.4.43.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
frr
Azure Linux 3.0
0:10.5.4-1.azl3
fixed