NULL Pointer Dereference in FRRouting OSPF Functionality Affects Multiple Versions
CVE-2025-61105

7.5HIGH

Key Information:

Vendor

FRRouting

Status
Vendor
CVE Published:
27 October 2025

What is CVE-2025-61105?

The FRRouting project has identified a vulnerability present in versions 4.0 through 10.4.1, where a NULL pointer dereference occurs in the show_vty_link_info function of the ospf_ext.c file. This flaw can be exploited by attackers to launch a Denial of Service (DoS) attack by sending specially crafted OSPF packets. Network administrators are urged to update to the latest versions or apply necessary patches to mitigate this issue and protect the integrity of their network services.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.