Description
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.
Problem types
Product status
4.1
4.2
4.3.0
Timeline
| 2026-03-30: | Advisory disclosed |
| 2026-03-30: | VulDB entry created |
| 2026-03-30: | VulDB entry last update |
Credits
Sunxj (VulDB User)
References
vuldb.com/vuln/354155 (VDB-354155 | osrg GoBGP bgp.go DecodeFromBytes off-by-one)
vuldb.com/vuln/354155/cti (VDB-354155 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/780179 (Submit #780179 | osrg GoBGP 4.3.0 Off-by-one Error)
github.com/osrg/gobgp/pull/3342
github.com/...ommit/67c059413470df64bc20801c46f64058e88f800f
github.com/osrg/gobgp/