Quagga is an open-source routing software suite that implements dynamic routing protocols for Unix-like systems and is widely embedded in network appliances, routers, and infrastructure where it handles BGP, OSPF, and RIP functions. Despite its focused product scope, the software occupies a prominent role in network infrastructure and has accumulated meaningful vulnerability exposure centered on memory-safety and input-handling defects. The recurring weakness classes—buffer-boundary violations, improper input validation, and double-free conditions—reflect the low-level packet parsing and protocol-state management inherent to a routing daemon that processes untrusted network traffic. Vulnerabilities affecting this vendor lean toward serious outcomes and have shown a moderate tendency to acquire public exploit code, making timely patching important for network operators maintaining Quagga deployments. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quagga over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5378MEDIUM The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is invalid. Arbitrary data from the | Feb 19, 2018 | 5.9 | 59 | NO | NO |
CVE-2018-5379CRITICAL The Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list and/or unknown attributes. A suc | Feb 19, 2018 | 9.8 | 51 | NO | NO |
CVE-2018-5381HIGH The Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capability_msg_parse function. The pars | Feb 19, 2018 | 7.5 | 39 | NO | NO |
CVE-2017-5495HIGH All versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service of Quagga daemons, or even the | Jan 24, 2017 | 7.5 | 35 | NO | NO |
CVE-2017-16227HIGH The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH siz | Oct 29, 2017 | 7.5 | 33 | NO | NO |
CVE-2016-2342HIGH The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-V | Mar 17, 2016 | 8.1 | 32 | NO | NO |
CVE-2016-4049HIGH The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (asse | May 23, 2016 | 7.5 | 28 | NO | NO |
CVE-2006-2223MEDIUM RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote a | May 5, 2006 | 5.0 | 27 | NO | YES |
CVE-2006-2224MEDIUM RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE p | May 5, 2006 | 5.0 | 26 | NO | YES |
CVE-2021-44038HIGH An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to | Nov 19, 2021 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quagga.
Media articles that mention a CVE ID that affects a product developed by Quagga — matched by CVE ID, not by vendor name.