Back

MEDIUM

FRRouting < 10.5.3 Integer Overflow in OSPF TLV Parser Functions

Published Apr 30, 2026

Description

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.

Affected products

Remediation

Red Hat statement

Moderate impact. This flaw in FRRouting's OSPF TLV parser functions can lead to a denial of service. An attacker with an established OSPF adjacency can send a specially crafted packet, triggering out-of-bounds memory reads and crashing routers within the OSPF area or autonomous system. Exploitation requires network proximity and an active OSPF peering relationship.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 30, 2026
Updated Oct 1, 2026
Reserved Feb 27, 2026
CISA Vulnrichment
Updated May 1, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 30, 2026
ENISA EUVD
Assigner VulnCheck
Published Apr 30, 2026
Updated Oct 1, 2026
Exploited since n/a
EUVD-2026-26418