Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37459

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

A flaw was found in FRRouting (FRR). An unauthenticated remote attacker can exploit an integer underflow vulnerability by supplying a specially crafted BGP (Border Gateway Protocol) UPDATE message. This issue can lead to a Denial of Service (DoS).

Отчет

This vulnerability allows an unauthenticated remote attacker to cause a denial of service via a specially crafted BGP UPDATE message. Due to this reason, this issue has been rated with an important severity.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8frrWill not fix
Red Hat Enterprise Linux 9frrWill not fix
Red Hat Enterprise Linux 10frrFixedRHSA-2026:2434708.06.2026
Red Hat Enterprise Linux 9frr10FixedRHSA-2026:2437008.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2466513frr: denial of service via crafted BGP UPDATE message

EPSS

Процентиль: 30%
0.00371
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
nvd
3 месяца назад

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

msrc
3 месяца назад

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
debian
3 месяца назад

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 all ...

CVSS3: 7.5
github
3 месяца назад

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

EPSS

Процентиль: 30%
0.00371
Низкий

7.5 High

CVSS3