{"id":"CVE-2026-5107","summary":"FRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control","details":"A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.","modified":"2026-07-15T22:54:09.024631Z","published":"2026-03-30T05:00:19.025Z","related":["SUSE-SU-2026:21550-1","SUSE-SU-2026:22026-1","SUSE-SU-2026:2454-1","SUSE-SU-2026:2455-1","SUSE-SU-2026:2457-1","openSUSE-SU-2026:10606-1","openSUSE-SU-2026:20682-1","openSUSE-SU-2026:20898-1"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-266","CWE-284"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5107.json"},"references":[{"type":"WEB","url":"https://github.com/FRRouting/frr/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5107.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5107"},{"type":"ADVISORY","url":"https://vuldb.com/submit/780123"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/354132"},{"type":"REPORT","url":"https://vuldb.com/vuln/354132/cti"},{"type":"FIX","url":"https://github.com/FRRouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045"},{"type":"FIX","url":"https://github.com/FRRouting/frr/pull/21098"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/frrouting/frr","events":[{"introduced":"c41ba202c3f821a43091781181c73772501034ae"},{"fixed":"7676cad65114aa23adde583d91d9d29e2debd045"}],"database_specific":{"cpe":["cpe:2.3:a:frrouting:frrouting:10.5.0:*:*:*:*:*:*:*","cpe:2.3:a:frrouting:frrouting:10.5.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"10.5.0"},{"last_affected":"10.5.0"},{"introduced":"10.5.1"},{"last_affected":"10.5.1"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["10.5.0","10.5.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5107.json","vanir_signatures_modified":"2026-07-15T22:54:09Z","vanir_signatures":[{"digest":{"line_hashes":["309858907047205237897580473095809074700","222615880213350509333864447474777056277","71382495430921216026194148424765862646","140982808662906853279900249895135436887"],"threshold":0.9},"id":"CVE-2026-5107-01c56c3f","signature_type":"Line","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"file":"bgpd/bgp_evpn_mh.c"},"deprecated":false},{"digest":{"function_hash":"48465980338777555228996229920367804521","length":1409},"id":"CVE-2026-5107-1fd1876d","signature_type":"Function","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"file":"bgpd/bgp_evpn_mh.c","function":"bgp_evpn_type4_route_process"},"deprecated":false},{"source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"file":"bgpd/rfapi/rfapi_rib.c"},"deprecated":false,"digest":{"line_hashes":["282147124414440420257133091010025652452","58116171703406344158986504369459898812","59805534075928271403927516560536479883","323087614189101801880787146968875531959","85110258112993758719432453781170511253","312160519202952621865589452403075420681","221762640638543859620609235853719657896","181604849225036855719507687995749630998","69837547169406747498179554913119530639"],"threshold":0.9},"id":"CVE-2026-5107-6318bf6c","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"function":"rfapiRibBi2Ri","file":"bgpd/rfapi/rfapi_rib.c"},"deprecated":false,"digest":{"function_hash":"157499238891552097237064193212862864683","length":2061},"id":"CVE-2026-5107-954baada"},{"deprecated":false,"digest":{"function_hash":"230143969083548005036764116062763434646","length":2599},"id":"CVE-2026-5107-98effdaa","signature_type":"Function","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"function":"process_type2_route","file":"bgpd/bgp_evpn.c"}},{"deprecated":false,"digest":{"line_hashes":["207262202442817487799008919024496480435","139402499805387138438827967829576008491","52474138479042036712732066317154248520","191388891584098983115847002952184619870","120415299796551961403836544837448706644","68703053602961138868412001709603524492","207442951457067792281084195098476060422"],"threshold":0.9},"id":"CVE-2026-5107-b08f2ba2","signature_type":"Line","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"file":"bgpd/bgp_evpn.c"}},{"deprecated":false,"digest":{"function_hash":"98706549729377899364542509360232606406","length":1851},"id":"CVE-2026-5107-c1c489bf","signature_type":"Function","signature_version":"v1","source":"https://github.com/frrouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045","target":{"file":"bgpd/bgp_evpn.c","function":"process_type3_route"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}