REDHAT-BUG-2464548: High severity Frrouting FRR vulnerability
Published May 1, 2026
·Updated
An off-by-one out-of-bounds write vulnerability in the bgpflowspecopdecode() function (bgpd/bgpflowspecutil.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Affected Software
1 affected component
Frrouting FRR=stable/10.0
Event History
May 1, 2026
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2464548?
The severity of REDHAT-BUG-2464548 is high, rated at 7.
2
How do I fix REDHAT-BUG-2464548?
To fix REDHAT-BUG-2464548, update to the latest stable version of FRRouting that addresses this vulnerability.
3
What type of vulnerability is REDHAT-BUG-2464548?
REDHAT-BUG-2464548 is an off-by-one out-of-bounds write vulnerability.
4
What can attackers do with REDHAT-BUG-2464548?
Attackers can exploit REDHAT-BUG-2464548 to cause a Denial of Service (DoS) by supplying a crafted FlowSpec component.
5
Which function is affected by REDHAT-BUG-2464548?
The bgp_flowspec_op_decode() function in bgpd/bgp_flowspec_util.c is affected by REDHAT-BUG-2464548.