Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37462

Опубликовано: 03 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

A flaw was found in gobgp. An integer underflow vulnerability in the BGPUpdate.DecodeFromBytes function allows a remote attacker to cause a Denial of Service (DoS) by sending a specially crafted BGP (Border Gateway Protocol) UPDATE message. This can disrupt network operations and make the affected system unavailable.

Отчет

This Important flaw in gobgp allows a remote, unauthenticated attacker to trigger a denial of service. By sending a specially crafted BGP UPDATE message, an integer underflow can occur, disrupting network operations and impacting the availability of services that rely on gobgp, such as those deployed within OpenShift Container Platform.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8Not affected
Red Hat OpenShift Container Platform 4redhat-user-workloads/art-imagesAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-191
https://bugzilla.redhat.com/show_bug.cgi?id=2484417github.com/osrg/gobgp: gobgp: Denial of Service via crafted BGP UPDATE message

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
nvd
2 месяца назад

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

CVSS3: 7.5
debian
2 месяца назад

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/b ...

CVSS3: 7.3
github
2 месяца назад

GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-37462