PT-2026-36829 · Frrouting+2 · Frrouting+2

·

CVE-2026-37458

·

Published

2026-05-04

·

Updated

2026-08-28

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FRRouting (FRR) versions stable/10.0 through stable/10.6
Description Missing input validation in the MP REACH NLRI component allows authenticated attackers to cause a Denial of Service (DoS) by supplying a crafted UPDATE message.
Recommendations Update to version 10.6.1-1.1.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86214
CVE-2026-37458
OPENSUSE-SU-2026:10721-1
OPENSUSE-SU-2026:20898-1
SUSE-SU-2026:22026-1
SUSE-SU-2026:2454-1
SUSE-SU-2026:2455-1
SUSE-SU-2026:2457-1
SUSE-SU-2026:2644-1
SUSE-SU-2026:3868-1
USN-8376-1

Affected Products

Frrouting
Linuxmint
Ubuntu