PT-2025-17424 · Gobgp+4 · Gobgp+4

Published

2025-04-20

·

Updated

2025-08-08

·

CVE-2025-43970

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 3.35.0
Description The issue arises from improper input length checking in the pkg/packet/mrt/mrt.go file, specifically failing to ensure the presence of 12 bytes or 36 bytes depending on the address family.
Recommendations For versions prior to 3.35.0, update to version 3.35.0 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09853
CVE-2025-43970
GHSA-HQHQ-HP5X-XP3W
GO-2025-3630
OPENSUSE-SU-2025:15017-1
USN-7661-1

Affected Products

Debian
Gobgp
Linuxmint
Red Os
Ubuntu