Описание
ELSA-2026-24340: frr security update (IMPORTANT)
[7.5.1-24.0.1]
- Fix POSTIN scriptlet [Orabug: 34712485]
[7.5.1-24]
- Fix off-by-one error in FlowSpec operator array bounds checking (CVE-2026-37457)
- Resolves: RHEL-174676
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
frr
7.5.1-24.0.1.el8_10
frr-selinux
7.5.1-24.0.1.el8_10
Oracle Linux x86_64
frr
7.5.1-24.0.1.el8_10
frr-selinux
7.5.1-24.0.1.el8_10
Связанные CVE
Связанные уязвимости
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op ...