Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7737

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.

A flaw was found in osrg GoBGP. A remote attacker can exploit an out-of-bounds read vulnerability within the BMP Parser component, specifically in the BMPPeerUpNotification.ParseBody and BMPStatisticsReport.ParseBody functions. This manipulation can lead to a denial of service, making the affected system unavailable.

Отчет

This is an Important denial of service vulnerability in osrg GoBGP. A remote attacker can trigger an out-of-bounds read within the BMP Parser by sending specially crafted BGP Monitoring Protocol messages, leading to service unavailability. The flaw's impact is significant due to its remote exploitability and direct effect on network routing stability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2464870github.com/osrg/gobgp: osrg GoBGP: Denial of service via out-of-bounds read in BMP Parser

EPSS

Процентиль: 46%
0.00631
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.

CVSS3: 5.3
debian
3 месяца назад

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by ...

CVSS3: 5.3
github
3 месяца назад

GoBGP has Improper Restriction of Operations within the Bounds of a Memory Buffer

EPSS

Процентиль: 46%
0.00631
Низкий

7.5 High

CVSS3