RHSA-2026:49511: Important: frr security update
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/frrto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10 - Upgrade
Upgrade
redhat/frr-debuginfoto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10 - Upgrade
Upgrade
redhat/frr-debugsourceto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10 - Upgrade
Upgrade
redhat/frr-selinuxto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10 - Upgrade
Upgrade
redhat/frrto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10.aa - Upgrade
Upgrade
redhat/frr-debuginfoto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10.aa - Upgrade
Upgrade
redhat/frr-debugsourceto a version that resolves this vulnerability.Fixed in 7.5.1-25.el8_10.aa - Upgrade
Upgrade
frr/FRRoutingto a version that resolves this vulnerability.Patch CVE-2026-37460
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49511?
The severity of RHSA-2026:49511 is classified as high with a score of 7.
What type of vulnerability is addressed in RHSA-2026:49511?
RHSA-2026:49511 addresses a Denial of Service vulnerability via a crafted BGP UPDATE message (CVE-2026-37460).
How do I fix RHSA-2026:49511?
To fix RHSA-2026:49511, it is recommended to apply the latest security update for the FRRouting software.
Which software versions are affected by RHSA-2026:49511?
RHSA-2026:49511 affects various versions of Red Hat's FRRouting software across multiple architectures.
What is the impact of vulnerability CVE-2026-37460 mentioned in RHSA-2026:49511?
CVE-2026-37460 can lead to a Denial of Service condition if exploited, affecting network routing capabilities.