Red Hat Security Advisory: frr security update
Two denial of service vulnerabilities were identified in FRRouting (FRR), a free software suite managing TCP/IP routing protocols. The issues involve crafted FlowSpec components and crafted BGP UPDATE messages that can cause service disruption. These vulnerabilities affect FRR versions included in Red Hat Enterprise Linux 10 up to version 10.4.3. Red Hat has released security updates addressing these issues. The severity of these vulnerabilities is rated as high by Red Hat Product Security.
AI Analysis
Technical Summary
FRRouting (FRR) contains two denial of service vulnerabilities: CVE-2026-37457, caused by a crafted FlowSpec component, and CVE-2026-37459, caused by a crafted BGP UPDATE message. Both vulnerabilities can be exploited to disrupt routing services. These issues affect FRR versions shipped with Red Hat Enterprise Linux 10, specifically versions from 10.0.0 up to and including 10.4.3. Red Hat has issued an important security advisory (RHSA-2026:24347) with updated FRR packages (version 10.4.4 and later) that fix these vulnerabilities. No CVSS scores are provided in the advisory.
Potential Impact
Successful exploitation of these vulnerabilities can cause denial of service conditions in FRRouting, potentially disrupting network routing operations on affected Red Hat Enterprise Linux 10 systems. This could impact network availability but does not indicate privilege escalation or data compromise based on the provided information.
Mitigation Recommendations
Red Hat has released updated FRR packages (version 10.4.4 and later) that address these denial of service vulnerabilities. Users of affected Red Hat Enterprise Linux 10 systems should apply the security update as described in Red Hat advisory RHSA-2026:24347. Details on applying the update are available at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated or required beyond applying the official patch.
Red Hat Security Advisory: frr security update
Description
Two denial of service vulnerabilities were identified in FRRouting (FRR), a free software suite managing TCP/IP routing protocols. The issues involve crafted FlowSpec components and crafted BGP UPDATE messages that can cause service disruption. These vulnerabilities affect FRR versions included in Red Hat Enterprise Linux 10 up to version 10.4.3. Red Hat has released security updates addressing these issues. The severity of these vulnerabilities is rated as high by Red Hat Product Security.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FRRouting (FRR) contains two denial of service vulnerabilities: CVE-2026-37457, caused by a crafted FlowSpec component, and CVE-2026-37459, caused by a crafted BGP UPDATE message. Both vulnerabilities can be exploited to disrupt routing services. These issues affect FRR versions shipped with Red Hat Enterprise Linux 10, specifically versions from 10.0.0 up to and including 10.4.3. Red Hat has issued an important security advisory (RHSA-2026:24347) with updated FRR packages (version 10.4.4 and later) that fix these vulnerabilities. No CVSS scores are provided in the advisory.
Potential Impact
Successful exploitation of these vulnerabilities can cause denial of service conditions in FRRouting, potentially disrupting network routing operations on affected Red Hat Enterprise Linux 10 systems. This could impact network availability but does not indicate privilege escalation or data compromise based on the provided information.
Mitigation Recommendations
Red Hat has released updated FRR packages (version 10.4.4 and later) that address these denial of service vulnerabilities. Users of affected Red Hat Enterprise Linux 10 systems should apply the security update as described in Red Hat advisory RHSA-2026:24347. Details on applying the update are available at https://access.redhat.com/articles/11258. No additional mitigation steps are indicated or required beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:24347
- Cve Count
- 2
- Additional Cves
- ["CVE-2026-37459"]
- State
- PUBLISHED
Threat ID: 6a27320ee29bf47b509bf30c
Added to database: 06/08/2026, 21:20:14 UTC
Last enriched: 08/03/2026, 22:26:18 UTC
Last updated: 09/14/2026, 22:01:33 UTC
Views: 693
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.