← Back to CVE Index
CVE-2026-37460
Disclosed 2026-06-03
Description
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
Severity & CVSS Score
7.5
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
| CWE-ID | Name |
|---|---|
| CWE-20 | Improper Input Validation |
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/pull/21098%2C | GitHub |
| https://github.com/FRRouting/frr | GitHub |
| https://github.com/FRRouting/frr/commit/7676cad65114aa23adde58 | GitHub |
Git Fixes
- 7676cad65114aa23adde583d91d9d29e2debd045
- 36f4098738627d724a72d37ef660a5d8eb1e8020
- 52c72c5ad8ccb491a9bab096002072667089d2d3
- 8f3f7ec6acd0ad14018f1c7a7a1e653266929f09
Raw Data
- CVE-2026-37460.cve.json — CVE record (JSON)
- CVE-2026-37460.frr.json — FRR-specific data (JSON)