This update for frr fixes the following issues
Update to frr 8.5.7:
* CVE-2026-5107: Fixed an improper access controls in EVPN Type-2 Route
Handler (bsc#1261013).
* CVE-2026-28532: Harden TE/SR TLV iteration against malformed lengths
(bsc#1263859).
* CVE-2026-37457: Fix off-by-one error in FlowSpec operator array bounds check
(bsc#1263863).
* CVE-2026-37458: Validate MP_REACH_NLRI attribute against incorrect next-hop
(bsc#1263974). DoS via a crafted UPDATE message (bsc#1263974).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.5
zypper in -t patch SUSE-2026-2454=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2454=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2454=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2454=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2454=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2454=1
* Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2454=1
* SUSE Linux Enterprise High Performance Computing ESPOS...
Read the Full Advisory* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586)
* libmlag_pb0-debuginfo-8.5.7-150500.4.43.1
* frr-debugsource-8.5.7-150500.4.43.1
* libfrrfpm_pb0-debuginfo-8.5.7-150500.4.43.1
* libfrr0-debuginfo-8.5.7-150500.4.43.1
* libfrrzmq0-8.5.7-150500.4.43.1
* libfrrospfapiclient0-8.5.7-150500.4.43.1
* libfrrsnmp0-debuginfo-8.5.7-150500.4.43.1
* libfrrcares0-debuginfo-8.5.7-150500.4.43.1
* libfrr_pb0-debuginfo-8.5.7-150500.4.43.1
* libfrrfpm_pb0-8.5.7-150500.4.43.1
* libfrrospfapiclient0-debuginfo-8.5.7-150500.4.43.1
* frr-8.5.7-150500.4.43.1
* libmlag_pb0-8.5.7-150500.4.43.1
* libfrrsnmp0-8.5.7-150500.4.43.1
* libfrr_pb0-8.5.7-150500.4.43.1
* frr-debuginfo-8.5.7-150500.4.43.1
* libfrrcares0-8.5.7-150500.4.43.1
* frr-devel-8.5.7-150500.4.43.1
* libfrr0-8.5.7-150500.4.43.1
* libfrrzmq0-debuginfo-8.5.7-150500.4.43.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* libmlag_pb0-debuginfo-8.5.7-150500.4.43.1
* frr-debugsource-8.5.7-150500.4.43.1
*...
Read the Full Advisory* bsc#1261013
* bsc#1263859
* bsc#1263863
* bsc#1263974
## References:
* https://www.suse.com/security/cve/CVE-2026-28532.html
* https://www.suse.com/security/cve/CVE-2026-37457.html
* https://www.suse.com/security/cve/CVE-2026-37458.html
* https://www.suse.com/security/cve/CVE-2026-5107.html
* https://bugzilla.suse.com/show_bug.cgi?id=1261013
* https://bugzilla.suse.com/show_bug.cgi?id=1263859
* https://bugzilla.suse.com/show_bug.cgi?id=1263863
* https://bugzilla.suse.com/show_bug.cgi?id=1263974
Get the latest Linux and open source security news straight to your inbox.