Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
Metrics
Affected Vendors & Products
References
History
Tue, 05 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Crafted MP_REACH_NLRI UPDATE in FRRouting 10.0-10.6 |
Tue, 05 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 04 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Frrouting
Frrouting frrouting |
|
| Vendors & Products |
Frrouting
Frrouting frrouting |
Mon, 04 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Crafted MP_REACH_NLRI UPDATE in FRRouting 10.0-10.6 | |
| Weaknesses | CWE-20 |
Mon, 04 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-05-04T00:00:00.000Z
Updated: 2026-05-05T16:03:14.025Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37458
Updated: 2026-05-05T15:46:44.596Z
Status : Received
Published: 2026-05-04T16:16:02.170
Modified: 2026-05-05T16:16:12.690
Link: CVE-2026-37458
No data.
ReportizFlow