Search CVE reports


Toggle filters

11 – 20 of 51 results


CVE-2025-61103

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61105

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61102

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61101

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61100

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Vulnerable —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2025-61099

Medium priority

Some fixes available 4 of 9

FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr Fixed Fixed Fixed Ignored —
quagga Not in release Not in release Not in release Vulnerable Vulnerable
Show less packages

CVE-2024-55553

Medium priority
Fixed

In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An attacker can use this to trigger...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr — Fixed Fixed Fixed —
quagga — Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-44070

Medium priority
Fixed

An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr — Fixed Fixed Fixed —
quagga — Not in release Not in release Fixed Fixed
Show less packages

CVE-2024-34088

Medium priority
Fixed

In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes,...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr — Fixed Fixed Not affected —
quagga — Not in release Not in release Not affected Not affected
Show less packages

CVE-2024-31951

Medium priority
Fixed

In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs...

2 affected packages

frr, quagga

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
frr — Fixed Fixed Not affected —
quagga — Not in release Not in release Not affected Not affected
Show less packages