PT-2026-36829 · Frrouting · Frrouting

Jiahao Lei

·

Published

2026-05-04

·

Updated

2026-05-11

·

CVE-2026-37458

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FRRouting (FRR) versions stable/10.0 through stable/10.6
Description Missing input validation in the MP REACH NLRI component allows authenticated attackers to cause a Denial of Service (DoS) by supplying a crafted UPDATE message.
Recommendations Update to version 10.6.1-1.1.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-37458
OPENSUSE-SU-2026:10721-1

Affected Products

Frrouting