Описание
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
A flaw was found in gobgp. An integer underflow vulnerability in the BGPUpdate.DecodeFromBytes function allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted BGP (Border Gateway Protocol) UPDATE message. This can disrupt network operations and make the affected system unavailable.
Отчет
This Important flaw in gobgp allows a remote, unauthenticated attacker to trigger a denial of service. By sending a specially crafted BGP UPDATE message, an integer underflow can occur, disrupting network operations and impacting the availability of services that rely on gobgp, such as those deployed within OpenShift Container Platform.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel8 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | redhat-user-workloads/art-images | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/b ...
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
EPSS
7.5 High
CVSS3