RHSA-2026:49527: Important: frr security, bug fix, and enhancement update
FRRouting is free software that manages TCP/IP based routing protocols. It supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. Security Fix(es): frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) Bug Fix(es) and Enhancement(s): Zebra is not installing the route in the kernel after flapping one of the physical link on the ocp worker node. [rhel-9.8.z] (JIRA:RHEL-152300) frr triggers SELinux denials when reading root's Python site-packages directory on RHEL-9 (JIRA:RHEL-176258) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: frr security, bug fix, and enhancement update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/frrto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1 - Upgrade
Upgrade
redhat/frr-debuginfoto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1 - Upgrade
Upgrade
redhat/frr-debugsourceto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1 - Upgrade
Upgrade
redhat/frr-selinuxto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1 - Upgrade
Upgrade
redhat/frrto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1.aa - Upgrade
Upgrade
redhat/frr-debuginfoto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1.aa - Upgrade
Upgrade
redhat/frr-debugsourceto a version that resolves this vulnerability.Fixed in 8.5.3-15.el9_8.1.aa - Upgrade
Upgrade
frr (FRRouting)to a version that resolves this vulnerability.Patch CVE-2026-37460 - Upgrade
Upgrade
frr (FRRouting)to a version that resolves this vulnerability.Patch JIRA:RHEL-176258 - Upgrade
Upgrade
rhel-9.8.zto a version that resolves this vulnerability.Patch JIRA:RHEL-152300
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49527?
The severity of RHSA-2026:49527 is classified as high with a score of 7.
What does RHSA-2026:49527 address?
RHSA-2026:49527 addresses security vulnerabilities, bug fixes, and enhancements in the frr package.
How do I fix RHSA-2026:49527?
To fix RHSA-2026:49527, users should apply the available updates for their respective Red Hat Enterprise Linux version.
Which systems are affected by RHSA-2026:49527?
RHSA-2026:49527 affects multiple Red Hat Enterprise Linux systems including IBM z Systems, ARM 64, x86_64, and Power.
When was RHSA-2026:49527 published?
RHSA-2026:49527 was published on August 3, 2026.