{"id":"AZL-85332","summary":"CVE-2026-28532 affecting package frr for versions less than 10.5.0-3","details":"FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.","modified":"2026-08-30T05:26:50Z","published":"2026-04-30T21:16:31Z","upstream":["CVE-2026-28532"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28532"}],"affected":[{"package":{"name":"frr","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/frr"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.5.0-3"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-85332.json"}}],"schema_version":"1.9.0"}