← Back to CVE Index
CVE-2026-37457
Disclosed 2026-05-01
Description
An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-787 | Out-of-bounds Write |
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c | GitHub |
Git Fixes
- 0e6882bc72c0278988a47b2f0f73b7a91099a25c
- b413dbc239841ce4d13824119df4be9c6f06647e
- 55479934df4d5db06b6f893a32c43cafbd2b5fdb
- a2d916ac819efd34c9a18d704aa01339accc3994
- bc106c9fa9565d98cc982bcedb5615f259453348
- a2d65c98d3571194ea13b9435ea90531a4142020
- 373d9d715c7a5524155493f7a5ea331b3407a62c
- 70dbd170fbc37570197102274614c9a4a2a9056a
Raw Data
- CVE-2026-37457.cve.json — CVE record (JSON)
- CVE-2026-37457.frr.json — FRR-specific data (JSON)