UbuntuUpdates.org

Package "frr"

Name: frr

Description:

FRRouting Internet routing protocol suite

Latest version: 10.4.1-3ubuntu1.1
Release: questing (25.10)
Level: updates
Repository: main
Homepage: https://www.frrouting.org

Links


Download "frr"


Other versions of "frr" in Questing

Repository Area Version
base main 10.4.1-3ubuntu1
base universe 10.4.1-3ubuntu1
security main 10.4.1-3ubuntu1.1
security universe 10.4.1-3ubuntu1.1
updates universe 10.4.1-3ubuntu1.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 10.4.1-3ubuntu1.1 2026-02-17 22:08:39 UTC

  frr (10.4.1-3ubuntu1.1) questing-security; urgency=medium

  * SECURITY UPDATE: multiple ospf security issues
    - debian/patches/CVE-2025-61xxx-1.patch: add null check for vty_out in
      check_tlv_size in ospfd/ospf_ext.c.
    - debian/patches/CVE-2025-61xxx-2.patch: fix NULL Pointer Deference
      when dumping link info in ospfd/ospf_ext.c.
    - debian/patches/CVE-2025-61xxx-3.patch: skip subsequent tlvs after
      invalid length in ospfd/ospf_ext.c, ospfd/ospf_ri.c, ospfd/ospf_te.c.
    - debian/patches/CVE-2025-61xxx-4.patch: reformat check_tlv_size macro
      in ospfd/ospf_ext.c, ospfd/ospf_ri.c, ospfd/ospf_te.c.
    - CVE-2025-61099, CVE-2025-61100, CVE-2025-61101, CVE-2025-61102,
      CVE-2025-61103, CVE-2025-61104, CVE-2025-61105, CVE-2025-61106,
      CVE-2025-61107

 -- Marc Deslauriers <email address hidden> Thu, 12 Feb 2026 09:27:07 -0500

CVE-2025-61099 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. Th
CVE-2025-61100 FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c.
CVE-2025-61101 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_
CVE-2025-61102 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c
CVE-2025-61103 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_e
CVE-2025-61104 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. Thi
CVE-2025-61105 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This
CVE-2025-61106 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.
CVE-2025-61107 FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.



About   -   Send Feedback to @ubuntu_updates