PT-2025-17425 · Gobgp+4 · Gobgp+4

Ivg

·

Published

2025-04-20

·

Updated

2025-08-08

·

CVE-2025-43971

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 3.35.0
Description An issue was discovered that allows attackers to cause a panic via a zero value for softwareVersionLen.
Recommendations For versions prior to 3.35.0, update to version 3.35.0 or later to resolve the issue. As a temporary workaround, consider implementing input validation to prevent zero values for softwareVersionLen until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09852
CVE-2025-43971
GHSA-7M35-VW2C-696V
GO-2025-3631
OPENSUSE-SU-2025:15017-1
USN-7661-1

Affected Products

Debian
Gobgp
Linuxmint
Red Os
Ubuntu