CVE-2025-43970

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
Configurations

Configuration 1 (hide)

cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*

History

08 May 2025, 15:45

Type Values Removed Values Added
References () https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0 - () https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0 - Patch
References () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - () https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 - Patch, Release Notes
Summary
  • (es) Se descubrió un problema en GOBGP antes de 3.35.0. PKG/Packet/MRT/MRT.GO no verifica correctamente la longitud de entrada, por ejemplo, asegurando que haya 12 bytes o 36 bytes (dependiendo de la familia de direcciones).
CPE cpe:2.3:a:osrg:gobgp:*:*:*:*:*:*:*:*
First Time Osrg
Osrg gobgp

21 Apr 2025, 02:15

Type Values Removed Values Added
Summary (en) An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g.. by ensuring that there are 12 bytes or 36 bytes (depending on the address family). (en) An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).

21 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-21 01:15

Updated : 2025-05-08 15:45


NVD link : CVE-2025-43970

Mitre link : CVE-2025-43970

CVE.ORG link : CVE-2025-43970


JSON object : View

Products Affected

osrg

  • gobgp
CWE
CWE-1284

Improper Validation of Specified Quantity in Input