CVE-2026-37457: High severity Frrouting FRR vulnerability
An off-by-one out-of-bounds write vulnerability in the bgpflowspecopdecode() function (bgpd/bgpflowspecutil.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.5.4-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-37457?
CVE-2026-37457 is classified as a Denial of Service vulnerability.
How do I fix CVE-2026-37457?
To fix CVE-2026-37457, upgrade to the latest version of FRRouting that addresses this vulnerability.
Which versions of FRRouting are affected by CVE-2026-37457?
CVE-2026-37457 affects only the stable/10.0 version of FRRouting.
Can CVE-2026-37457 be exploited remotely?
Yes, CVE-2026-37457 can be exploited remotely by supplying a crafted FlowSpec component.
What impact does CVE-2026-37457 have on systems?
The impact of CVE-2026-37457 is a potential Denial of Service, which can disrupt the availability of affected systems.