Описание
ELSA-2026-49527: frr security, bug fix, and enhancement update (IMPORTANT)
[8.5.3-15.1]
- Resolves: RHEL-193234 - input validation fixes for EVPN NLRI and ENCAP/VNC packet parsing
[8.5.3-15]
- Resolves: RHEL-176258 - AVC when reading user's site-packages
[8.5.3-14]
- Resolves: RHEL-152300 - ignored route in the kernel after flapping interface
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
frr
8.5.3-15.el9_8.1
frr-selinux
8.5.3-15.el9_8.1
Oracle Linux x86_64
frr
8.5.3-15.el9_8.1
frr-selinux
8.5.3-15.el9_8.1
Связанные CVE
Связанные уязвимости
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) ...