Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1063-1

Опубликовано: 26 мар. 2026
Источник: suse-cvrf

Описание

Security update for frr

This update for frr fixes the following issues:

Security issues:

  • CVE-2025-61099: NULL Pointer Dereference in FRRouting (bsc#1252838).
  • CVE-2025-61100: NULL Pointer Dereference in FRRouting (bsc#1252829).
  • CVE-2025-61101: NULL Pointer Dereference in FRRouting (bsc#1252833).
  • CVE-2025-61102: NULL Pointer Dereference in FRRouting (bsc#1252835).
  • CVE-2025-61103: NULL pointer dereference in show_vty_ext_link_lan_adj_sid() in ospf_ext.c (bsc#1252810).
  • CVE-2025-61104: NULL pointer dereference in show_vty_unknown_tlv() in ospf_ext.c (bsc#1252811).
  • CVE-2025-61105: NULL pointer dereference in show_vty_link_info() in ospf_ext.c (bsc#1252761).
  • CVE-2025-61106: NULL pointer dereference in show_vty_ext_pref_pref_sid() in ospf_ext.c (bsc#1252812).

Non-security issues:

  • Fix /var/run leftovers in logrotate config file, create /var/log and /var/lib via tmpfiles.d (jsc#PED-14796).

Список пакетов

SUSE Linux Enterprise Module for Server Applications 15 SP7
libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6
frr-8.5.6-150500.4.36.1
frr-devel-8.5.6-150500.4.36.1
libfrr0-8.5.6-150500.4.36.1
libfrr_pb0-8.5.6-150500.4.36.1
libfrrcares0-8.5.6-150500.4.36.1
libfrrfpm_pb0-8.5.6-150500.4.36.1
libfrrospfapiclient0-8.5.6-150500.4.36.1
libfrrsnmp0-8.5.6-150500.4.36.1
libfrrzmq0-8.5.6-150500.4.36.1
libmlag_pb0-8.5.6-150500.4.36.1

Описание

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки

Описание

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet.


Затронутые продукты
SUSE Linux Enterprise Module for Server Applications 15 SP7:libmlag_pb0-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-8.5.6-150500.4.36.1
openSUSE Leap 15.6:frr-devel-8.5.6-150500.4.36.1
openSUSE Leap 15.6:libfrr0-8.5.6-150500.4.36.1

Ссылки
Уязвимость SUSE-SU-2026:1063-1