PatchSiren

FRRouting CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FRRouting CVE published 2026-09-14

CVE-2022-42917

A TOCTOU Race Condition vulnerability exists in FRRouting FRR before 8.5, allowing the service user to escalate privileges to root by monitoring and replacing configuration files. This vulnerability is caused by a combination of touch and chown, and defenders should assess exposure and prioritize verification and remediation. The service user can monitor the configuration directory (/etc/frr) and replace [truncated]

HIGH FRRouting CVE published 2026-05-04

CVE-2026-37459

CVE-2026-37459 is a high-severity vulnerability in FRRouting (FRR) that allows attackers to cause a Denial of Service (DoS) via a crafted BGP UPDATE message. The vulnerability is caused by an integer underflow in FRR versions stable/10.0 to stable/10.6. The vulnerability has a CVSS score of 7.5 and is classified as HIGH. The CVE was published on May 4, 2026, and last modified on June 30, 2026.