frr: FRRouting: Denial of Service via crafted BGP UPDATE message
Published Jun 3, 2026
7.5
HIGHCVSS 3.1
EPSS 0.61%
Description
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 10
frr-0:10.4.4-1.el10_2
Fixed · RHSA-2026:24347
Red Hat Enterprise Linux 8
frr-0:7.5.1-25.el8_10
Fixed · RHSA-2026:49511
Red Hat Enterprise Linux 9
frr-0:8.5.3-15.el9_8.1
Fixed · RHSA-2026:49527
Red Hat Enterprise Linux 9
frr10-0:10.4.3-3.el9_8.2
Fixed · RHSA-2026:49607
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | frr-0:10.4.4-1.el10_2 | Fixed | RHSA-2026:24347 |
| Red Hat Enterprise Linux 8 | frr-0:7.5.1-25.el8_10 | Fixed | RHSA-2026:49511 |
| Red Hat Enterprise Linux 9 | frr-0:8.5.3-15.el9_8.1 | Fixed | RHSA-2026:49527 |
| Red Hat Enterprise Linux 9 | frr10-0:10.4.3-3.el9_8.2 | Fixed | RHSA-2026:49607 |
No package ranges for this CVE.
Remediation
Red Hat statement
This Important flaw in FRRouting (FRR) allows a remote, unauthenticated attacker to trigger a denial of service by sending a specially crafted BGP UPDATE message. This can lead to the disruption of network services managed by FRR instances configured to handle BGP traffic. The vulnerability does not require complex attack vectors or user interaction, making it a significant availability risk for affected systems.
Red Hat mitigation
To mitigate this issue, restrict access to FRRouting's BGP services to only trusted peers and networks. Implement firewall rules to limit inbound connections to BGP port 179 (TCP) to known, legitimate BGP neighbors. If BGP is not actively used, consider disabling the BGP daemon within FRR to eliminate the attack surface. Warning: Modifying firewall rules or FRR configuration may impact network connectivity and requires careful planning and testing. A restart of the FRR service may be required for changes to take effect.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 4, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.61% (0.00609) | 47.29th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.34% (0.00339) | 25.49th | v5 (v2026.06.15) |
| Jun 4, 2026 | 0.02% (0.00017) | 4.20th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-37460 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2484385 Issue Tracking
- https://github.com/FRRouting/frr
- https://github.com/FRRouting/frr/commit/7676cad65114aa23adde58
- https://github.com/FRRouting/frr/pull/21098%2C
- https://nvd.nist.gov/vuln/detail/CVE-2026-37460
- https://www.cve.org/CVERecord?id=CVE-2026-37460
Change history (0)
No recorded changes yet.