PT-2025-29308 · Gobgp+1 · Gobgp+1
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
osrg GoBGP versions up to 3.37.0
Description:
A problematic issue exists in the
SplitRTR function of the pkg/packet/rtr/rtr.go file. This can lead to an out-of-bounds read, and the attack can be launched remotely. The complexity of the attack is high, and exploitability is difficult.Recommendations:
Apply the patch e748f43496d74946d14fed85c776452e47b99d64 to fix this issue.
Exploit
Fix
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Gobgp