Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85646.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-85646
Upstream
Published
2026-05-01T18:16:14Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-37457 affecting package frr for versions less than 10.5.4-1
Details

An off-by-one out-of-bounds write vulnerability in the bgpflowspecopdecode() function (bgpd/bgpflowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

References

Affected packages

Azure Linux:3 / frr

Package

Name
frr
Purl
pkg:rpm/azure-linux/frr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.5.4-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85646.json"