[Git][security-tracker-team/security-tracker][master] Add CVE-2026-37460/frr

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jun 5 08:23:15 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b452a9a4 by Salvatore Bonaccorso at 2026-06-05T09:22:57+02:00
Add CVE-2026-37460/frr

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -505,7 +505,8 @@ CVE-2026-37462 (An integer underflow in the BGPUpdate.DecodeFromBytes function (
 	- gobgp 4.4.0-1
 	NOTE: https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d (v4.4.0)
 CVE-2026-37460 (Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) ...)
-	TODO: check
+	- frr 10.6.1-1
+	NOTE: https://github.com/FRRouting/frr/commit/36f4098738627d724a72d37ef660a5d8eb1e8020 (frr-10.6.1)
 CVE-2026-36748 (RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripti ...)
 	NOT-FOR-US: RockRMS
 CVE-2026-36618 (Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to v ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b452a9a419a4e69f84bef1f13934373001010017

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b452a9a419a4e69f84bef1f13934373001010017
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260605/82239536/attachment.htm>


More information about the debian-security-tracker-commits mailing list