openSUSE-SU-2026:20898-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20898-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20898-1
Upstream
CVE (4)
Related
Published
2026-06-03T09:46:09Z
Modified
2026-06-06T18:24:32Z
Summary
Security update for frr
Details

This update for frr fixes the following issues:

  • CVE-2026-5107: Fixed an improper access controls in EVPN Type-2 Route Handler (bsc#1261013).
  • CVE-2026-28532: Harden TE/SR TLV iteration against malformed lengths (bsc#1263859).
  • CVE-2026-37457: Fix off-by-one error in FlowSpec operator array bounds check (bsc#1263863).
  • CVE-2026-37458: Validate MP_REACH_NLRI attribute against incorrect next-hop (bsc#1263974).
References

Affected packages