Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c. Upstream bug: https://github.com/FRRouting/frr/issues/10503
Created frr tracking bugs for this issue: Affects: fedora-all [bug 2072483]