Description
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Published: 2026-05-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An off‑by‑one out‑of‑bounds write occurs in the bgp_flowspec_op_decode() function of FRRouting’s FlowSpec processing. The defect corrupts memory as a crafted FlowSpec component is parsed, which can crash the BGP daemon and render the routing service unavailable. The primary effect is a denial of service; no information disclosure or privilege escalation is described.

Affected Systems

FRRouting FRR version stable/10.0 is affected. No other vendors or products appear to be impacted based on the current information.

Risk and Exploitability

The CVSS score is 7.5, indicating a significant severity. EPSS is not available, so the exact exploitation likelihood cannot be quantified. The vulnerability is listed as not in the CISA KEV catalog. The likely attack vector is through network traffic that includes a malicious FlowSpec component sent to the FRRouting instance. An attacker with network reach to the BGP service can trigger a crash, causing service interruption.

Generated by OpenCVE AI on May 2, 2026 at 00:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FRRouting to a version that includes the patch for this bug
  • If an upgrade is not immediately feasible, disable FlowSpec parsing or drop FlowSpec messages from untrusted peers
  • Apply network segmentation or firewall rules to restrict inbound traffic to the BGP process to known, authenticated peers

Generated by OpenCVE AI on May 2, 2026 at 00:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 02 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title Off‑by‑One Out‑of‑Bounds Write in FRRouting FlowSpec Parsing Causes DoS

Fri, 01 May 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Frrouting
Frrouting frrouting
Vendors & Products Frrouting
Frrouting frrouting

Fri, 01 May 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 01 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
References

Subscriptions

Frrouting Frrouting
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-01T18:16:41.085Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37457

cve-icon Vulnrichment

Updated: 2026-05-01T18:13:50.404Z

cve-icon NVD

Status : Received

Published: 2026-05-01T18:16:14.770

Modified: 2026-05-01T19:16:30.247

Link: CVE-2026-37457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T00:15:06Z

Weaknesses