Search CVE reports


Toggle filters

1 – 10 of 73 results


CVE-2022-42917

Medium priority
Needs evaluation

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-37460

Medium priority

Some fixes available 4 of 7

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Fixed —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-37459

Medium priority

Some fixes available 2 of 5

An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Not affected Not affected Not affected —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-37458

Medium priority

Some fixes available 4 of 8

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Needs evaluation —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-37457

Medium priority

Some fixes available 4 of 8

An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Needs evaluation —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-28532

Medium priority

Some fixes available 4 of 8

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Needs evaluation —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-5107

Medium priority

Some fixes available 4 of 7

A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Not affected Fixed Fixed Fixed —
quagga Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-61107

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61106

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61104

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages