# CVE-2026-28532

> Vulnerability · severity: **MEDIUM** (CVSS 6.5).

## Description

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement continues unchecked. Attackers with an established OSPF adjacency can send a crafted LS Update packet with a malicious Type 10 or Type 11 Opaque LSA to trigger out-of-bounds memory reads and crash all affected routers in the OSPF area or autonomous system.

## Key facts

- **CVE ID:** CVE-2026-28532
- **Published:** 2026-04-30
- **CVSS severity:** MEDIUM
- **CVSS base score:** 6.5
- **CWE codes:** CWE-125, CWE-190

## Affected products

- `frrouting:frrouting`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-28532

## Citation

> AI Analytics. CVE-2026-28532. Retrieved 2026-07-03 from https://api.ai-analytics.org/cve/CVE-2026-28532. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*