Description
Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
Published: 2026-05-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FRRouting (FRR) versions stable/10.0 through stable/10.6 suffer from missing input validation in the MP_REACH_NLRI component. An authenticated attacker can send a specially crafted UPDATE message causing the FRR process to crash or become unresponsive, resulting in a denial of service. The flaw is a CWE‑20 improper input validation issue triggered by malformed routing protocol messages.

Affected Systems

The affected system is FRRouting, commonly deployed on routers and routing platforms. Vulnerable releases include stable/10.0 up to stable/10.6. No CNA vendor or product name is listed, but the software is identified via the GitHub references.

Risk and Exploitability

The CVSS score is 6.5, indicating moderate severity, and the EPSS score is less than 1%, suggesting a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to authenticate to the FRRouting instance or have access to a peer capable of injecting OSPF UPDATE messages. Based on the description, the attack vector is inferred to be network‑level, leveraging OSPF MP_REACH_NLRI messages sent from an authenticated or trusted peer.

Generated by OpenCVE AI on May 5, 2026 at 18:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the patch from the FRRouting GitHub commit 8102a8aeceb9f86fdfe1f80cd77080522bab69c8 which validates MP_REACH_NLRI input.
  • Upgrade to FRRouting stable/10.7 or newer where the vulnerability has been addressed.
  • If upgrading immediately is not feasible, configure the network to filter or drop malformed MP_REACH_NLRI updates from untrusted peers and consider rate‑limiting OSPF UPDATE traffic to mitigate the impact of malformed requests.

Generated by OpenCVE AI on May 5, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 11 May 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*

Sat, 09 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title frr: denial of service via crafted UPDATE message
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 05 May 2026 18:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP_REACH_NLRI UPDATE in FRRouting 10.0-10.6

Tue, 05 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 04 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Frrouting
Frrouting frrouting
Vendors & Products Frrouting
Frrouting frrouting

Mon, 04 May 2026 17:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Crafted MP_REACH_NLRI UPDATE in FRRouting 10.0-10.6
Weaknesses CWE-20

Mon, 04 May 2026 16:00:00 +0000

Type Values Removed Values Added
Description Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
References

Subscriptions

Frrouting Frrouting
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-05T16:03:14.025Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37458

cve-icon Vulnrichment

Updated: 2026-05-05T15:46:44.596Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-04T16:16:02.170

Modified: 2026-05-11T19:52:46.943

Link: CVE-2026-37458

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-04T00:00:00Z

Links: CVE-2026-37458 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-05T18:15:29Z

Weaknesses