A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
CVSS Details
- CVSS 4.0 Base Score: 2.3 (LOW)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 4.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade frr | Jun 7, 2026 | Jun 7, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 30, 2026 |
| Suse | — | Upgrade libfrrzmq0Upgrade libmgmt_be_nb0Upgrade libfrrfpm_pb0Upgrade libfrrospfapiclient0Upgrade libfrrsnmp0Upgrade frrUpgrade frr-develUpgrade libfrr0Upgrade libfrr_pb0Upgrade libfrrcares0 | May 26, 2026 | May 5, 2026 |
| Ubuntu | — | Upgrade frr (Ubuntu Pro)Upgrade frr | Apr 16, 2026 | Mar 30, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 22, 2026 | Mar 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub