High severity7.5NVD Advisory· Published May 4, 2026· Updated Jul 15, 2026
CVE-2026-37459
CVE-2026-37459
Description
An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords5 versionspkg:rpm/almalinux/frrpkg:rpm/almalinux/frr-selinuxpkg:rpm/almalinux/frr10pkg:rpm/almalinux/frr10-selinuxpkg:rpm/opensuse/frr&distro=openSUSE%20Tumbleweed
< 10.4.4-1.el10_2+ 4 more
- (no CPE)range: < 10.4.4-1.el10_2
- (no CPE)range: < 10.4.4-1.el10_2
- (no CPE)range: < 10.4.3-3.el9_8
- (no CPE)range: < 10.4.3-3.el9_8
- (no CPE)range: < 10.6.1-1.1
Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2026:24347nvd
- access.redhat.com/errata/RHSA-2026:24370nvd
- access.redhat.com/security/cve/CVE-2026-37459nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/FRRouting/frr/commit/693a2e02687cdc9d16501275e05136edea9650d9nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-37459.jsonnvd
News mentions
1- Patch Tuesday - May 2026Rapid7 Blog · May 13, 2026