CVE-2026-28532
published 2026-04-30CVE-2026-28532: FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t…
PriorityP428medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.22%
13.2th percentile
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | — | — |
| frrouting | frr | < 10.5.3 | 10.5.3 |
| frrouting | frrouting | < 10.5.3 | 10.5.3 |
| ubuntu | frr | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.0MEDIUM
vendor_ubuntu6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FRRouting FRR up to 10.5.3 Segment Routing TLV Parser TLV_SIZE integer overflow
vuldb·2026-04-30·CVSS 6.0
CVE-2026-28532 [MEDIUM] FRRouting FRR up to 10.5.3 Segment Routing TLV Parser TLV_SIZE integer overflow
A vulnerability was found in FRRouting FRR up to 10.5.3. It has been declared as critical. This impacts the function TLV_SIZE of the component Segment Routing TLV Parser. Such manipulation leads to integer overflow.
This vulnerability is referenced as CVE-2026-28532. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
GHSA-wjc3-2qjv-c8fp: FRRouting before 10
ghsa_unreviewed·2026-04-30
CVE-2026-28532 [MEDIUM] CWE-125 GHSA-wjc3-2qjv-c8fp: FRRouting before 10
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.
Ubuntu
FRR vulnerabilities
vendor_ubuntu·2026-06-03·CVSS 6.0
CVE-2026-37459 [MEDIUM] FRR vulnerabilities
Title: FRR vulnerabilities
Summary: Several security issues were fixed in FRR.
It was discovered that FRR incorrectly handled certain OSPF Traffic
Engineering and Segment Routing TLVs. An attacker could possibly use this
issue to cause FRR to crash, resulting in a denial of service.
(CVE-2026-28532)
It was discovered that FRR incorrectly handled certain BGP FlowSpec
components. An attacker could possibly use this issue to cause FRR to
crash, resulting in a denial of service. (CVE-2026-37457)
It was discovered that FRR did not properly validate certain MP_REACH_NLRI
messages. An authenticated user could possibly use this issue to cause FRR
to crash, resulting in a denial of service. (CVE-2026-37458)
It was discovered that FRR incorrectly handled processing certain BGP
UPDATE messages.
Red Hat
FRRouting: frr: FRRouting: Denial of Service due to integer overflow in OSPF TLV parser functions
vendor_redhat·2026-04-30·CVSS 6.0
CVE-2026-28532 [MEDIUM] CWE-190 FRRouting: frr: FRRouting: Denial of Service due to integer overflow in OSPF TLV parser functions
FRRouting: frr: FRRouting: Denial of Service due to integer overflow in OSPF TLV parser functions
FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.
A flaw was found in FRRouting. An integer overflow vulnerability exists in several OSPF Traffic Engineering and Segment Routing TL
No detection rules found.
No public exploits indexed.
2026-04-30
Published