CVE-2025-43971

An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Configurations

Configuration 1 (hide)

cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*

History

08 May 2025, 15:57

Type Values Removed Values Added
CPE cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
First Time Osrg
Osrg gobgp
References () https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986 - () https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986 - Patch
References () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - Patch, Release Notes
Summary
  • (es) Se descubrió un problema en GOBGP antes de 3.35.0. PKG/PACKET/BGP/BGP.GO permite a los atacantes causar un pánico a través de un valor cero para SoftwareVersionLen.

21 Apr 2025, 02:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6
CWE CWE-193

21 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 01:15

Updated : 2025-05-08 15:57


NVD link : CVE-2025-43971

Mitre link : CVE-2025-43971

CVE.ORG link : CVE-2025-43971


JSON object : View

Products Affected

osrg

  • gobgp
CWE
CWE-193

Off-by-one Error