Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86214.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-86214
Upstream
Published
2026-05-04T16:16:02Z
Modified
2026-08-28T17:47:58Z
Summary
CVE-2026-37458 affecting package frr for versions less than 10.5.4-1
Details

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

References

Affected packages

Azure Linux:3 / frr

Package

Name
frr
Purl
pkg:rpm/azure-linux/frr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.5.4-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86214.json"