CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Debolezza
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Prodotti interessati
- frrouting frrouting
Riferimenti
- https://github.com/FRRouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c
- https://access.redhat.com/errata/RHSA-2026:24340
- https://access.redhat.com/errata/RHSA-2026:24347
- https://access.redhat.com/errata/RHSA-2026:24370
- https://access.redhat.com/errata/RHSA-2026:24371
- https://access.redhat.com/security/cve/CVE-2026-37457
Trova il bug prima di un attaccante.
Accedi con GitHub e avvia il tuo primo audit in meno di un minuto. Il piano gratuito non richiede carta di credito.