CVE-2026-37460: Input Validation
Published Jun 3, 2026
·Updated
Missing input validation in the rfapiRibBi2Ri() function (rfapirib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Affected Software
1 affected component
Frrouting FRRouting (FRR)>=10.0<=10.6
Event History
Jun 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-37460?
The severity of CVE-2026-37460 is rated high with a CVSS score of 7.5.
2
What does CVE-2026-37460 affect?
CVE-2026-37460 affects the FRRouting software versions stable/10.0 to stable/10.6.
3
How does CVE-2026-37460 allow an attack?
CVE-2026-37460 allows attackers to cause a Denial of Service (DoS) by supplying a crafted BGP UPDATE message.
4
What is the impact of CVE-2026-37460?
The impact of CVE-2026-37460 is that it can lead to a Denial of Service, making the system unresponsive.
5
How can I mitigate CVE-2026-37460?
To mitigate CVE-2026-37460, it's recommended to upgrade to the latest version of FRRouting that includes the fix.