← Vulnerability feed

Vulnerability record · CVE-2025-61101 · published 27 October 2025

CVE-2025-61101: Frrouting null pointer dereference vulnerability

Frrouting · Frrouting

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

7.5 CVSS 3.1 High EPSS 0.47% · top 62.0% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61101 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-38406Frrouting vulnerabilitybgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow."EPSS 0.94%9.8CVE-2023-41361Frrouting classic buffer overflow vulnerabilityAn issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.EPSS 0.90%9.1CVE-2023-41359Frrouting out-of-bounds read vulnerabilityAn issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no ch…EPSS 1.2%9.1CVE-2023-41360Frrouting out-of-bounds read vulnerabilityAn issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.EPSS 1.2%9.1CVE-2022-37032Frrouting out-of-bounds read vulnerabilityAn out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capabi…EPSS 2.2%8.1CVE-2022-37035Frrouting race condition vulnerabilityAn issue was discovered in bgpd in FRRouting (FRR) 8.3. In bgp_notify_send_with_data() and bgp_process_packet() in bgp_packet.c, there is a possible …EPSS 2.6%7.8CVE-2022-26125Frrouting memory buffer overflow vulnerabilityBuffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.EPSS 1.0%7.8CVE-2022-26126Frrouting memory buffer overflow vulnerabilityBuffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notific…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-61101), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.