CVE-2026-37460

EUVD-2026-34083
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.13%
Debian logo
Debian Releases
Debian Product
Codename
frr
bookworm
no-dsa
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
10.7.0-1
fixed
sid
10.7.0-2
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
frr
focal
Fixed 7.2.1-1ubuntu0.2+esm4
released
jammy
Fixed 8.1-1ubuntu1.15
released
noble
Fixed 8.4.4-1.1ubuntu6.6
released
questing
Fixed 10.4.1-3ubuntu1.2
released
resolute
not-affected
quagga
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
frr
RHEL 8
0:7.5.1-25.el8_10
fixed
RHEL 9
0:8.5.3-15.el9_8.1
fixed
frr-selinux
RHEL 8
0:7.5.1-25.el8_10
fixed
RHEL 9
0:8.5.3-15.el9_8.1
fixed
frr10
RHEL 9
0:10.4.3-3.el9_8.2
fixed
frr10-selinux
RHEL 9
0:10.4.3-3.el9_8.2
fixed