← Back to CVE Index
CVE-2026-37459
Disclosed 2026-05-04
Description
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-400 | Uncontrolled Resource Consumption |
| CWE-191 | Integer Underflow (Wrap or Wraparound) |
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/693a2e02687cdc9d16501275e05136edea9650d9 | GitHub |
Git Fixes
- 693a2e02687cdc9d16501275e05136edea9650d9
- 854c4c579cbf3d799730bf7d4a584186954ce1da
- eb02dc7a070db2d5da4f564fd8c725bbce5c3e14
- ec285878bc703fbe8807db9481e48626c851b13e
Raw Data
- CVE-2026-37459.cve.json — CVE record (JSON)
- CVE-2026-37459.frr.json — FRR-specific data (JSON)