[DSA 6322-1] frr security update
Aron Xu <[email protected]> Thu, 04 Jun 2026 17:40:16 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6322-1 [email protected] https://www.debian.org/security/ Aron Xu June 05, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : frr CVE ID : CVE-2023-3748 CVE-2024-27913 CVE-2024-31950 CVE-2024-31951 CVE-2024-34088 CVE-2025-61099 CVE-2025-61100 CVE-2025-61101 CVE-2025-61102 CVE-2025-61103 CVE-2025-61104 CVE-2025-61105 CVE-2025-61106 CVE-2025-61107 CVE-2026-5107 CVE-2026-28532 CVE-2026-37457 CVE-2026-37458 Debian Bug : Several vulnerabilities were discovered in FRRouting (frr), a suite of internet routing protocol daemons. A remote attacker could trigger these issues by sending specially crafted protocol packets to a vulnerable daemon, resulting in denial of service (infinite loops, NULL pointer dereferences and crashes) or potentially the execution of arbitrary code through out-of-bounds reads and writes and buffer overflows. The flaws affect packet and attribute parsing in the BGP daemon (including FlowSpec, EVPN/VNC NLRI and MP_REACH_NLRI handling), the OSPF daemon (Traffic Engineering, Segment Routing and Opaque LSA processing) and the babeld daemon. For the oldstable distribution (bookworm), these problems have been fixed in version 8.4.4-1.1~deb12u2. For the stable distribution (trixie), these problems have been fixed in version 10.3-3+deb13u1. We recommend that you upgrade your frr packages. For the detailed security status of frr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/frr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmoht1gACgkQ+GQ1dHE8 m676nAgA094uJCBNzH5T5Qa/ce27ovdL1jh62uD50PyN+b072l5sTKbPQqmlholg lh4268Im53Tjpa5zBhJQUPLWGI0olOYSEY2U3fOG+/h293c0naaMkoU7w96hswoM rxfiU5+31/wLteb7TlQKzM1jqmvcwOzCEn2PRti9IU3QO4kLObXERP/SPLsZxuUy 8UykyCJpIsk0ARmENU2a0hf+HA7mLo5+dxTOz9OYhu5Iu7Nu+/VZ7m4Q6i2eA3V7 cWJGdCJZb2HJjlXbvyoUINlNzaAXs082NZubJUEr/yuMBQXa+4SaqTiy7D7LYurj BvOoijj/RoHGHbib76OLZJb7LOzqQA== =ZtXt -----END PGP SIGNATURE-----