Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85332.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-85332
Upstream
Published
2026-04-30T21:16:31Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-28532 affecting package frr for versions less than 10.5.0-3
Details

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16t accumulator variable truncates uint32t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.

References

Affected packages

Azure Linux:3 / frr

Package

Name
frr
Purl
pkg:rpm/azure-linux/frr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.5.0-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85332.json"