{"id":"CLSA-2026-1778238289","summary":"frr: Fix of 4 CVEs","details":"- CVE-2022-43681: fix bgpd crash on malformed BGP OPEN messages with insufficient data\n- CVE-2022-40318: fix out-of-bounds read in bgp_open_option_parse with extended option params\n- CVE-2023-31489: fix out-of-bounds read in BGP Long-lived Graceful-Restart capability parsing\n- CVE-2023-46752: fix bgpd crash on malformed MP_REACH_NLRI packets","modified":"2026-05-27T11:36:01.318369114Z","published":"2026-05-08T11:17:29Z","upstream":["CVE-2022-40318","CVE-2022-43681","CVE-2023-31489","CVE-2023-46752"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1778238289.html"}],"affected":[{"package":{"name":"frr","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/frr?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.3.1-5.el9_2.2.alma.tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1778238289.json"}},{"package":{"name":"frr-selinux","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/frr-selinux?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.3.1-5.el9_2.2.alma.tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1778238289.json"}}],"schema_version":"1.7.5"}