Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37458

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

A flaw was found in FRRouting (FRR). An authenticated remote attacker can exploit a missing input validation vulnerability in the MP_REACH_NLRI component by supplying a specially crafted UPDATE message. This issue can lead to a Denial of Service (DoS).

Отчет

This vulnerability allows an authenticated remote attacker to cause a denial of service via a specially crafted UPDATE message. Due to this reason, this issue has been rated with a moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10frrOut of support scope
Red Hat Enterprise Linux 8frrOut of support scope
Red Hat Enterprise Linux 9frrOut of support scope
Red Hat Enterprise Linux 9frr10Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2465680frr: denial of service via crafted UPDATE message

EPSS

Процентиль: 16%
0.00249
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 месяца назад

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

CVSS3: 6.5
nvd
3 месяца назад

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

msrc
3 месяца назад

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

CVSS3: 6.5
debian
3 месяца назад

Missing input validation in the MP_REACH_NLRI component of FRRouting ( ...

CVSS3: 6.5
github
3 месяца назад

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

EPSS

Процентиль: 16%
0.00249
Низкий

6.5 Medium

CVSS3