Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1057-1

Опубликовано: 26 мар. 2026
Источник: suse-cvrf

Описание

Security update for frr

This update for frr fixes the following issues:

  • CVE-2025-61099: NULL Pointer Dereference in FRRouting (bsc#1252838).
  • CVE-2025-61100: NULL Pointer Dereference in FRRouting (bsc#1252829).
  • CVE-2025-61101: NULL Pointer Dereference in FRRouting (bsc#1252833).
  • CVE-2025-61102: NULL Pointer Dereference in FRRouting (bsc#1252835).
  • CVE-2025-61103: NULL pointer dereference in show_vty_ext_link_lan_adj_sid() in ospf_ext.c (bsc#1252810).
  • CVE-2025-61104: NULL pointer dereference in show_vty_unknown_tlv() in ospf_ext.c (bsc#1252811).
  • CVE-2025-61105: NULL pointer dereference in show_vty_link_info() in ospf_ext.c (bsc#1252761).
  • CVE-2025-61106: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c (bsc#1252812).
  • CVE-2025-61107: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c (bsc#1252813).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
frr-8.5.6-8.9.1
frr-devel-8.5.6-8.9.1
libfrr0-8.5.6-8.9.1
libfrrcares0-8.5.6-8.9.1
libfrrospfapiclient0-8.5.6-8.9.1
libfrrsnmp0-8.5.6-8.9.1

Описание

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:frr-devel-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrr0-8.5.6-8.9.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libfrrcares0-8.5.6-8.9.1

Ссылки