CVE-2016-1245: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BUFSIZ is system-dependent.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Quagga Quagga: up to and including 1.0.20160315

Published 2017-02-22. Last modified 2026-06-17.