{"id":"openSUSE-SU-2026:20898-1","summary":"Security update for frr","details":"This update for frr fixes the following issues:\n\n- CVE-2026-5107: Fixed an improper access controls in EVPN Type-2 Route Handler (bsc#1261013).\n- CVE-2026-28532: Harden TE/SR TLV iteration against malformed lengths (bsc#1263859).\n- CVE-2026-37457: Fix off-by-one error in FlowSpec operator array bounds check (bsc#1263863).\n- CVE-2026-37458: Validate MP_REACH_NLRI attribute against incorrect next-hop (bsc#1263974).\n","modified":"2026-06-06T18:24:23.927599025Z","published":"2026-06-03T09:46:09Z","related":["CVE-2026-28532","CVE-2026-37457","CVE-2026-37458","CVE-2026-5107"],"upstream":["CVE-2026-28532","CVE-2026-37457","CVE-2026-37458","CVE-2026-5107"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263859"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28532"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-37457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-37458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-5107"}],"schema_version":"1.7.5"}