Security / Responsible Disclosure

Vulnerabilities discovered by the FRR team affecting older versions of FRR are patched and documented using CVEs. Below are all filed CVEs. If you encounter a security issue you’d like to report, please use the (private) FRR security handling mailing list.

Name Versions Affected Disclosure Date Severity
CVE-2017-15865 2.0.0
3.0.0
Nov 8, 2017 Medium
CVE-2019-5892 2.x
3.0 ~ 3.0.3
4
5.0 ~ 5.0.1
6.0 ~ 6.0.1
Jan 10, 2019 High