PT-2025-17426 · Gobgp+4 · Gobgp+4

Published

2025-04-20

·

Updated

2025-08-08

·

CVE-2025-43972

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 3.35.0
Description An issue was discovered that allows an attacker to cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
Recommendations For versions prior to 3.35.0, update to version 3.35.0 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-09851
CVE-2025-43972
GHSA-MFVV-MGF6-Q25R
GO-2025-3632
OPENSUSE-SU-2025:15017-1
USN-7661-1

Affected Products

Debian
Gobgp
Linuxmint
Red Os
Ubuntu