frr-8.5.3-13.el9_8
エラータID: AXSA:2026-1304:03
Release date:
Sunday, July 19, 2026 - 17:36
Subject:
frr-8.5.3-13.el9_8
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD.
Security Fix(es):
* frr: denial of service via crafted FlowSpec component (CVE-2026-37457)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Solution:
Update packages.
CVEs:
CVE-2026-37457
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Additional Info:
N/A
Download:
SRPMS
- frr-8.5.3-13.el9_8.src.rpm
MD5: ee97afd1898b89ef05103bff0def1aa8
SHA-256: ae89434e728f8ce6c2d4d325b7b535570265ecf1e53f656f419762a92b45d747
Size: 9.46 MB
Asianux Server 9 for x86_64
- frr-8.5.3-13.el9_8.x86_64.rpm
MD5: d9fa2fe600883ee0ab23cf3b5cdc70a4
SHA-256: 541fa50726f47ec77e3c93fd0b51e78a3628d1bf21783bca5502d8dff1641ba9
Size: 4.79 MB - frr-selinux-8.5.3-13.el9_8.noarch.rpm
MD5: dd5daf93bf07919c22c3b7faa5a598ed
SHA-256: d8f4beb41bea0320cbf8d211a7df79a5dded89b46c34add33cde7eae7e48162a
Size: 23.68 kB