This update for frr fixes the following issues:
- CVE-2026-5107: Fixed an improper access controls in EVPN Type-2 Route Handler (bsc#1261013).
- CVE-2026-28532: Harden TE/SR TLV iteration against malformed lengths (bsc#1263859).
- CVE-2026-37457: Fix off-by-one error in FlowSpec operator array bounds check (bsc#1263863).
- CVE-2026-37458: Validate MP_REACH_NLRI attribute against incorrect next-hop (bsc#1263974).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-884=1
- openSUSE Leap 16.0:
frr-10.2.6-160000.1.1
frr-devel-10.2.6-160000.1.1
libfrr0-10.2.6-160000.1.1
libfrr_pb0-10.2.6-160000.1.1
libfrrcares0-10.2.6-160000.1.1
libfrrfpm_pb0-10.2.6-160000.1.1
libfrrospfapiclient0-10.2.6-160000.1.1
libfrrsnmp0-10.2.6-160000.1.1
libfrrzmq0-10.2.6-160000.1.1
libmgmt_be_nb0-10.2.6-160000.1.1
* bsc#1261013
* bsc#1263859
* bsc#1263863
* bsc#1263974
References:
* https://www.suse.com/security/cve/CVE-2026-28532.html
* https://www.suse.com/security/cve/CVE-2026-37457.html
* https://www.suse.com/security/cve/CVE-2026-37458.html
* https://www.suse.com/security/cve/CVE-2026-5107.html
Get the latest Linux and open source security news straight to your inbox.