{"id":"CLSA-2025-1762363302","summary":"frr: Fix of 4 CVEs","details":"- CVE-2022-36440: fix heap-buffer-overflow in peek_for_as4_capability\n  when reading BGP OPEN extended optional parameters\n- CVE-2023-31490: fix insufficient stream data validation in BGP\n  prefix SID attributes processing\n- CVE-2023-38407: fix out-of-bounds read in BGP labeled unicast parsing\n- CVE-2023-41909: fix implicit withdrawal handling for BGP flowspec\n  without attributes","modified":"2026-05-27T11:16:20.072533678Z","published":"2025-11-05T17:21:48Z","upstream":["CVE-2022-36440","CVE-2023-31490","CVE-2023-38407","CVE-2023-41909"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1762363302.html"}],"affected":[{"package":{"name":"frr","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/frr?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.3.1-5.el9.2.alma.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1762363302.json"}},{"package":{"name":"frr-selinux","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/frr-selinux?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.3.1-5.el9.2.alma.tuxcare.els2"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1762363302.json"}}],"schema_version":"1.7.5"}