REDHAT-BUG-2484385: Input Validation
Published Jun 3, 2026
·Updated
Missing input validation in the rfapiRibBi2Ri() function (rfapirib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Affected Software
1 affected component
Frrouting FRRouting (FRR)>=10.0<=10.6
Event History
Jun 3, 2026
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2484385?
The severity of REDHAT-BUG-2484385 is high, rated at 7.
2
How do I fix REDHAT-BUG-2484385?
To fix REDHAT-BUG-2484385, update the FRRouting software to a version that includes the necessary input validation patch.
3
What type of vulnerability is identified in REDHAT-BUG-2484385?
REDHAT-BUG-2484385 is an input validation vulnerability that can lead to a Denial of Service.
4
Which function is affected by REDHAT-BUG-2484385?
The rfapiRibBi2Ri() function in rfapi_rib.c is affected by REDHAT-BUG-2484385.
5
Can REDHAT-BUG-2484385 be exploited remotely?
Yes, REDHAT-BUG-2484385 can be exploited remotely by sending a crafted BGP UPDATE message.