Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09988

Опубликовано: 30 мар. 2026
Источник: fstec
CVSS3: 4.2
CVSS2: 3.6
EPSS Низкий

Описание

Уязвимость программного средства реализации сетевой маршрутизации на Unix-подобных системах FRRouting связана с некорректным присваиванием привилегий. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, повысить свои привилегии

Вендор

Canonical Ltd.
Сообщество свободного программного обеспечения
ООО «Ред Софт»

Наименование ПО

Ubuntu
Debian GNU/Linux
РЕД ОС
FRRouting

Версия ПО

20.04 LTS (Ubuntu)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
22.04 LTS (Ubuntu)
24.04 LTS (Ubuntu)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
до 10.5.4 (FRRouting)

Тип ПО

Операционная система
Сетевое средство

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 20.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Canonical Ltd. Ubuntu 22.04 LTS
Canonical Ltd. Ubuntu 24.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 13
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Низкий уровень опасности (базовая оценка CVSS 2.0 составляет 3,6)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 4,2)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/advisories/GHSA-27p7-fq6v-hh4m
https://github.com/FRRoutingouting/FRRouting
https://github.com/FRRoutingouting/FRRouting/
https://github.com/FRRoutingouting/FRRouting/commit/7676cad65114aa23adde583d91d9d29e2debd045
https://github.com/FRRoutingouting/FRRouting/pull/21098
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-5107
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-5107
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-5107

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 20%
0.00279
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 4.2
redos
26 дней назад

Уязвимость frr

CVSS3: 4.2
ubuntu
4 месяца назад

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.

CVSS3: 4.2
redhat
4 месяца назад

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.

CVSS3: 4.2
nvd
4 месяца назад

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.

CVSS3: 4.2
msrc
4 месяца назад

FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control

EPSS

Процентиль: 20%
0.00279
Низкий

4.2 Medium

CVSS3

3.6 Low

CVSS2