========================================================================== Ubuntu Security Notice USN-8376-1 June 03, 2026 frr vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in FRR. Software Description: - frr: FRRouting suite of internet protocols Details: It was discovered that FRR incorrectly handled certain OSPF Traffic Engineering and Segment Routing TLVs. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-28532) It was discovered that FRR incorrectly handled certain BGP FlowSpec components. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37457) It was discovered that FRR did not properly validate certain MP_REACH_NLRI messages. An authenticated user could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37458) It was discovered that FRR incorrectly handled processing certain BGP UPDATE messages. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 25.04 and Ubuntu 25.10. (CVE-2026-37459) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS frr 10.5.1-1ubuntu4.1 Ubuntu 25.10 frr 10.4.1-3ubuntu1.4 Ubuntu 24.04 LTS frr 8.4.4-1.1ubuntu6.7 Ubuntu 22.04 LTS frr 8.1-1ubuntu1.16 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8376-1 CVE-2026-28532, CVE-2026-37457, CVE-2026-37458, CVE-2026-37459 Package Information: https://launchpad.net/ubuntu/+source/frr/10.5.1-1ubuntu4.1 https://launchpad.net/ubuntu/+source/frr/10.4.1-3ubuntu1.4 https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu6.7 https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.16
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in FRR. Software Description: - frr: FRRouting suite of internet protocols Details: It was discovered that FRR incorrectly handled certain OSPF Traffic Engineering and Segment Routing TLVs. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-28532) It was discovered that FRR incorrectly handled certain BGP FlowSpec components. An attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37457) It was discovered that FRR did not properly validate certain MP_REACH_NLRI messages. An authenticated user could possibly use this issue to cause FRR to crash, resulting in a denial of service. (CVE-2026-37458) It was discovered that FRR incorrectly handled processing certain BGP UPDATE messages. ...
Read the Full AdvisoryThe problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS frr 10.5.1-1ubuntu4.1 Ubuntu 25.10 frr 10.4.1-3ubuntu1.4 Ubuntu 24.04 LTS frr 8.4.4-1.1ubuntu6.7 Ubuntu 22.04 LTS frr 8.1-1ubuntu1.16 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-8376-1
CVE-2026-28532, CVE-2026-37457, CVE-2026-37458, CVE-2026-37459
https://launchpad.net/ubuntu/+source/frr/10.5.1-1ubuntu4.1 https://launchpad.net/ubuntu/+source/frr/10.4.1-3ubuntu1.4 https://launchpad.net/ubuntu/+source/frr/8.4.4-1.1ubuntu6.7 https://launchpad.net/ubuntu/+source/frr/8.1-1ubuntu1.16
Get the latest Linux and open source security news straight to your inbox.