CVE-2025-43973

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*

History

08 May 2025, 15:57

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en GOBGP antes de 3.35.0. PKG/PACKET/RTR/RTR.GO no verifica que la longitud de entrada corresponde a una situación en la que todos los bytes están disponibles para un mensaje RTR.
CPE cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
First Time Osrg
Osrg gobgp
References () https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe - () https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe - Patch
References () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - Patch, Release Notes

21 Apr 2025, 02:15

Type Values Removed Values Added
CWE CWE-193
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8

21 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 01:15

Updated : 2025-05-08 15:57


NVD link : CVE-2025-43973

Mitre link : CVE-2025-43973

CVE.ORG link : CVE-2025-43973


JSON object : View

Products Affected

osrg

  • gobgp
CWE
CWE-193

Off-by-one Error