Описание
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.
A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.
Отчет
GoBGP is vulnerable to denial of service via nil pointer dereference when processing a malformed BGP UPDATE containing an unrecognized well-known Path Attribute. A remote unauthenticated BGP peer who can send UPDATE messages to the daemon may crash the GoBGP process and disrupt routing availability. No Red Hat products currently ship GoBGP; exposure is limited to upstream or custom deployments that run affected 4.3.0 builds.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/metallb-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.
GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...
GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute
7.5 High
CVSS3