← Vulnerability feed

Vulnerability record · CVE-2021-44038 · published 19 November 2021

CVE-2021-44038: Quagga link following vulnerability

Quagga · Quagga

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

7.8 CVSS 3.1 High EPSS 0.79% · top 45.6% CWE-59 · Link following
7.8CVSS 3.1 base score, v2 7.2
0.79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.suse.com/show_bug.cgi?id=1191890 ExploitIssue TrackingThird Party Advisory
https://github.com/Quagga/quagga/releases Release NotesThird Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1191890 ExploitIssue TrackingThird Party Advisory
https://github.com/Quagga/quagga/releases Release NotesThird Party Advisory

Track CVE-2021-44038 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5379Quagga double free vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 can double-free memory when processing certain forms of UPDATE message, containing cluster-list a…EPSS 38%9.8CVE-2016-1245Quagga memory buffer overflow vulnerabilityIt was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…EPSS 3.7%8.2CVE-2017-3224Quagga insufficient verification of data authenticity vulnerabilityOpen Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNum…EPSS 1.1%8.1CVE-2016-2342Quagga memory buffer overflow vulnerabilityThe bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…EPSS 12%7.5CVE-2018-5381Quagga vulnerabilityThe Quagga BGP daemon (bgpd) prior to version 1.2.3 has a bug in its parsing of "Capabilities" in BGP OPEN messages, in the bgp_packet.c:bgp_capabili…EPSS 30%7.5CVE-2017-16227Quagga improper input validation vulnerabilityThe aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…EPSS 19%7.5CVE-2017-5495Quagga memory buffer overflow vulnerabilityAll versions of Quagga, 0.93 through 1.1.0, are vulnerable to an unbounded memory allocation in the telnet 'vty' CLI, leading to a Denial-of-Service …EPSS 19%7.5CVE-2016-4049Quagga improper input validation vulnerabilityThe bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to …EPSS 4.6%

Source: NIST National Vulnerability Database (record CVE-2021-44038), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.