CVE-2025-43970

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Configurations

No configuration.

History

21 Apr 2025, 02:15

Type Values Removed Values Added
Summary (en) An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g.. by ensuring that there are 12 bytes or 36 bytes (depending on the address family). (en) An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).

21 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 01:15

Updated : 2025-04-21 14:23


NVD link : CVE-2025-43970

Mitre link : CVE-2025-43970

CVE.ORG link : CVE-2025-43970


JSON object : View

Products Affected

No product.

CWE
CWE-1284

Improper Validation of Specified Quantity in Input