Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37457

Опубликовано: 01 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

A flaw was found in FRRouting (FRR). A remote attacker can exploit an off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function by supplying a specially crafted FlowSpec component. This issue can lead to a Denial of Service (DoS).

Отчет

This vulnerability allows an unauthenticated remote attacker to cause a denial of service via a specially crafted FlowSpec component. Due to this reason, this issue has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2464548frr: denial of service via crafted FlowSpec component

EPSS

Процентиль: 32%
0.00389
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

CVSS3: 7.5
nvd
3 месяца назад

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

CVSS3: 7.5
msrc
3 месяца назад

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

CVSS3: 7.5
debian
3 месяца назад

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op ...

rocky
около 2 месяцев назад

Important: frr security update

EPSS

Процентиль: 32%
0.00389
Низкий

7.5 High

CVSS3