|
|
Log in / Subscribe / Register

Ubuntu alert USN-8376-1 (frr)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8376-1] FRR vulnerabilities
Date:  Wed, 03 Jun 2026 17:19:09 +0000
Message-ID:  <E1wUpFF-0005mi-Js@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8376-1 June 03, 2026 frr vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in FRR. Software Description: - frr: FRRouting suite of internet protocols Details: It was discovered that FRR incorrectly handled certain OSPF Traffic Engineering and Segment Routing TLVs. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-28532) It was discovered that FRR incorrectly handled certain BGP FlowSpec components. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37457) It was discovered that FRR did not properly validate certain MP_REACH_NLRI messages. An authenticated user could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37458) It was discovered that FRR incorrectly handled processing certain BGP UPDATE messages. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-37459) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS frr 10.5.1-1ubuntu4.1 Ubuntu 25.10 frr 10.4.1-3ubuntu1.4 Ubuntu 24.04 LTS frr 8.4.4-1.1ubuntu6.7 Ubuntu 22.04 LTS frr 8.1-1ubuntu1.16 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8376-1 CVE-2026-28532, CVE-2026-37457, CVE-2026-37458, CVE-2026-37459 Package Information: https://launchpad.net/ubuntu/+source/frr/10.5.1-1ubuntu4.1 https://launchpad.net/ubuntu/+source/frr/10.4.1-3ubuntu1.4 https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu6.7 https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.16


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmogYF4ACgkQcpJm3tlz hgHWIQ/9FsV/FuJpOOIIaBkt6jUIO//TB54F9i3cC0SJrAx+d2eSdKvsptREAPD4 ronU5Nzfl1KobaqEppF05vz5iq6tQMAekxVBQVUQ2wXVqIpmQTStQHqk6PB99t6v 5qcx7ISi153cWdlQXYBQbW2pcIToH8oWNGcIVapH26p5UqCTSFuxqbS7APMae1Ds 2D1XiajJTXM3QZ89IgAu0ji/HoD7/RSm5nBqBKI6bFp2QWfrxPy+iwoqpcUyqi66 PbS6ssTKWS5HeKYUQNG9VwbSarGqsKIWAH6hLgnLA7zGSAdQzEqvU9sfRFJ+v3Ix Rb9s2XAFGU+d5+jzrMYXzWJ2kJTjjpc2Qcmou4ic6EiCfgGONgp083UKIXquCzsA GA9fLLMSS6XNgA92paKivavCNC+hOg6jUyrrxyAAhVVKQSa7vU5e9y4CdAlAOr5p zFQ3fD9MXHzKIWnZv3/CfIphuxtSOMTDOBCbwAZn/YkHsID+bMcVJij1ZKHm6FWU 46VMPebSmpHv2Fh4qugEPn/kGsKGKUtDB6movodlClS+pGKDlBMwY+0lGJ/ji+2f 73KwT94t+oGwDL+ttmrbsIyelhZbVQxkawEFD/++lspHziBycYujKZ3bG4UDcsZk wTYJKU0yaJPfMhKFYwRIPIF0C1Kq+DxDJkfpbQ1CVl26kOB+PJk= =k81p -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds