Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41642

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.

A flaw was found in GoBGP 4.3.0. A malformed BGP UPDATE with an unrecognized Path Attribute marked as well-known is not rejected cleanly, triggering a nil pointer dereference that crashes the GoBGP daemon. Fixed in GoBGP 4.4.0.

Отчет

GoBGP is vulnerable to denial of service via nil pointer dereference when processing a malformed BGP UPDATE containing an unrecognized well-known Path Attribute. A remote unauthenticated BGP peer who can send UPDATE messages to the daemon may crash the GoBGP process and disrupt routing availability. No Red Hat products currently ship GoBGP; exposure is limited to upstream or custom deployments that run affected 4.3.0 builds.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2467703github.com/osrg/gobgp: golang: GoBGP: Denial of Service via malformed BGP UPDATE message

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.

CVSS3: 7.5
nvd
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked as "Well-known," the daemon fails to interrupt the message handling flow. This results in an illegal memory access and a full process crash (panic). This issue has been patched in version 4.4.0.

CVSS3: 7.5
debian
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...

CVSS3: 7.5
github
3 месяца назад

GoBGP has Remote Denial of Service (Panic) via Malformed Well-known Path Attribute

7.5 High

CVSS3