Home

Description

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

PUBLISHED Reserved 2026-04-06 | Published 2026-06-03 | Updated 2026-06-05 | Assigner mitre

References

github.com/FRRouting/frr/pull/21098,

github.com/FRRouting/frr

github.com/FRRouting/frr/commit/7676cad65114aa23adde58

cve.org (CVE-2026-37460)

nvd.nist.gov (CVE-2026-37460)

Download JSON