Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41643

Опубликовано: 07 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.

A flaw was found in GoBGP. A remote attacker could send a specially crafted Border Gateway Protocol (BGP) UPDATE message that exploits improper handling of 4-byte Autonomous System (AS) attributes, causing an internal slice index shift. This leads to a runtime error, resulting in a Denial of Service (DoS) condition.

Отчет

This Moderate denial of service flaw in GoBGP is not expected to affect Red Hat products. The vulnerable code path related to malformed BGP UPDATE messages and 4-byte AS attributes is not present in the execution environment of affected Red Hat components, such as netshoot and OpenShift's metallb-rhel8.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/metallb-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1285
https://bugzilla.redhat.com/show_bug.cgi?id=2467704github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message

EPSS

Процентиль: 42%
0.00542
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.

CVSS3: 7.5
nvd
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.

CVSS3: 7.5
debian
3 месяца назад

GoBGP is an open source Border Gateway Protocol (BGP) implementation i ...

CVSS3: 7.5
github
3 месяца назад

GoBGP has Remote Denial of Service (Panic) in UpdatePathAttrs4ByteAs via Malformed BGP UPDATE

EPSS

Процентиль: 42%
0.00542
Низкий

7.5 High

CVSS3