CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Zwakheid
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Getroffen producten
- frrouting frrouting
Bronnen
- https://github.com/FRRouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c
- https://access.redhat.com/errata/RHSA-2026:24340
- https://access.redhat.com/errata/RHSA-2026:24347
- https://access.redhat.com/errata/RHSA-2026:24370
- https://access.redhat.com/errata/RHSA-2026:24371
- https://access.redhat.com/security/cve/CVE-2026-37457
Vind de bug voordat een aanvaller dat doet.
Log in met GitHub en start je eerste audit binnen een minuut. Voor het gratis abonnement is geen creditcard nodig.