[CLSA-2026:1786095204] frr: Fix of CVE-2026-37460
Type:
security
Severity:
Important
Release date:
2026-08-07 09:33:34 UTC
Description:
- CVE-2026-37460: fix missing input validation in the rfapiRibBi2Ri() RFP-option parser (bgpd/rfapi/rfapi_rib.c) allowing a bgpd DoS via a crafted BGP UPDATE with a short or zero-length VNC RFPOPTION subTLV. Scoped to the rfapi_rib.c hunk of upstream 7676cad6 to match NVD, which defines this CVE as rfapiRibBi2Ri() only; the same commit's bgp_evpn.c and bgp_evpn_mh.c hunks belong to CVE-2026-5107 and are not included
CVEs fixed:
Updated packages:
  • frr-8.5.3-9.el9_6.1.tuxcare.els2.x86_64.rpm
    sha:fcbff8318edcd7f0652207e24ca926b7e212022a6168e945674b99921f6688c5
  • frr-selinux-8.5.3-9.el9_6.1.tuxcare.els2.noarch.rpm
    sha:907564785201bdcb330a80a7f427ef637bf7de016f55ee434a26cecf3f533b82
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.