[CLSA-2026:1778238289] frr: Fix of 4 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-05-08 11:17:29 UTC
Description:
- CVE-2022-43681: fix bgpd crash on malformed BGP OPEN messages with insufficient data - CVE-2022-40318: fix out-of-bounds read in bgp_open_option_parse with extended option params - CVE-2023-31489: fix out-of-bounds read in BGP Long-lived Graceful-Restart capability parsing - CVE-2023-46752: fix bgpd crash on malformed MP_REACH_NLRI packets
Updated packages:
  • frr-8.3.1-5.el9_2.2.alma.tuxcare.els4.x86_64.rpm
    sha:53d1b6c30f03ef3293e6ac370a3c7424a6d1acba288b42fe8cac1509f656ba4e
  • frr-selinux-8.3.1-5.el9_2.2.alma.tuxcare.els4.noarch.rpm
    sha:2fe7f43975a160f748707183cb67c6a04834b40f3f90fe2bbc6b1f30990bd9b0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.