RHSA-2026:49607: Important: frr10 security, bug fix, and enhancement update
FRRouting is free software that manages TCP/IP based routing protocols. It takes a multi-server and multi-threaded approach to resolve the current complexity of the Internet. FRRouting supports BGP4, OSPFv2, OSPFv3, ISIS, RIP, RIPng, PIM, NHRP, PBR, EIGRP and BFD. FRRouting is a fork of Quagga.Security Fix(es): frr: FRRouting: Denial of Service via crafted BGP UPDATE message (CVE-2026-37460) Bug Fix(es) and Enhancement(s): frr10 triggers SELinux denials when reading root's Python site-packages directory on RHEL-9 (JIRA:RHEL-222338) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Other sources
Important: frr10 security, bug fix, and enhancement update
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/frr10to a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-debuginfoto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-debugsourceto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10-selinuxto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2 - Upgrade
Upgrade
redhat/frr10to a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
redhat/frr10-debuginfoto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
redhat/frr10-debugsourceto a version that resolves this vulnerability.Fixed in 10.4.3-3.el9_8.2.aa - Upgrade
Upgrade
frr10to a version that resolves this vulnerability.Patch CVE-2026-37460 - Compensating control
If updating to the referenced frr10 security/bugfix update is delayed, mitigate potential DoS exposure from crafted BGP UPDATE messages by limiting BGP connectivity to trusted peers only (reduce reachable BGP attack surface).