RHSA-2026:49607: Important: frr10 security, bug fix, and enhancement update
FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga.Security Fix(es): frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) Bug Fix(es) and Enhancement(s): frr10 triggers SELinux denials when reading root's Python site-packages directory on RHEL-9 (JIRA:RHEL-222338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: frr10 security, bug fix, and enhancement update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/frr10to a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-debuginfoto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-debugsourceto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-selinuxto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10to a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
redhat/frr10-debuginfoto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
redhat/frr10-debugsourceto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
frr10to a version that resolves this vulnerability.Patch CVE-2026-37460 - Compensating control
If updating to the referenced frr10 security/bugfix update is delayed, mitigate potential DoS exposure from crafted BGP UPDATE messages by limiting BGP connectivity to trusted peers only (reduce reachable BGP attack surface).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49607?
The severity of RHSA-2026:49607 is categorized as high with a score of 7.
How do I fix RHSA-2026:49607?
To fix RHSA-2026:49607, you should apply the latest updates provided for the affected FRRouting packages.
What vulnerabilities are addressed by RHSA-2026:49607?
RHSA-2026:49607 addresses security vulnerabilities and includes bug fixes and enhancements for the FRRouting software.
Which software packages are affected by RHSA-2026:49607?
The affected software packages include redhat/frr10, redhat/frr10-debuginfo, and redhat/frr10-debugsource among others.
When was RHSA-2026:49607 published?
RHSA-2026:49607 was published on August 3, 2026.