frr10-10.4.3-3.el9_8

エラータID: AXSA:2026-1301:02

Release date: 
Sunday, July 19, 2026 - 16:58
Subject: 
frr10-10.4.3-3.el9_8
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga.

Security Fix(es):

* frr: denial of service via crafted FlowSpec component (CVE-2026-37457)
* frr: denial of service via crafted BGP UPDATE message (CVE-2026-37459)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
CVE-2026-37459
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. frr10-10.4.3-3.el9_8.src.rpm
    MD5: fd0c2c1cf11d4757f46b8127ef13308d
    SHA-256: 68cf560ffca7131bf6503417bd3c1bf2899977cb1020a63ae54aeff0f13e2e6d
    Size: 10.87 MB

Asianux Server 9 for x86_64
  1. frr10-10.4.3-3.el9_8.x86_64.rpm
    MD5: ab201c6456a62e6a852ebbba1040c36a
    SHA-256: 9ba465404149d26e7ed1320c0e2512844d150e81017a9527fd5614fb8a64b333
    Size: 6.77 MB
  2. frr10-selinux-10.4.3-3.el9_8.noarch.rpm
    MD5: 9feec4a44203e796f4e57c8b77e91057
    SHA-256: 2c7ea2c56f1416bae9a278c257b005d2ecbbef76e406814bd8233c9562f3557f
    Size: 23.54 kB