


Perceptive Security
SOC/SIEM Consultancy

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attack…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 20:05:47
Source:
nvd.nist.gov
Network Infrastructure
An off-by-one out-of-bounds write vulnerability has been discovered in FRRouting (FRR) stable/10.0. The vulnerability exists in the bgp_flowspec_op_decode() function within the bgpd/bgp_flowspec_util.c file. Attackers can exploit this vulnerability by supplying a crafted FlowSpec component to cause a Denial of Service (DoS) condition. The vulnerability affects the BGP FlowSpec implementation, which is used for traffic filtering and flow specification in BGP routing. This represents a significant security risk for network infrastructure using FRRouting software.
Technical details
Mitigation steps:
Affected products:
FRRouting
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-37457
https://github.com/FRRouting/frr/commit/0e6882bc72c0278988a47b2f0f73b7a91099a25c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
