CVE-2025-43973

An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
Configurations

Configuration 1 (hide)

cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*

History

08 May 2025, 15:57

Type Values Removed Values Added
CPE cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-193
First Time Osrg
Osrg gobgp
References () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - Patch, Release Notes
References () https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe - () https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe - Patch

21 Apr 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 01:15

Updated : 2025-05-08 15:57


NVD link : CVE-2025-43973

Mitre link : CVE-2025-43973


JSON object : View

Products Affected

osrg

  • gobgp
CWE
CWE-193

Off-by-one Error