CVE-2025-7464

A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of the file pkg/packet/rtr/rtr.go. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The name of the patch is e748f43496d74946d14fed85c776452e47b99d64. It is recommended to apply a patch to fix this issue.
Configurations

No configuration.

History

15 Jul 2025, 13:14

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad clasificada como problemática en osrg GoBGP hasta la versión 3.37.0. La función SplitRTR del archivo pkg/packet/rtr/rtr.go se ve afectada. La manipulación provoca lecturas fuera de los límites. El ataque puede ejecutarse en remoto. Es un ataque de complejidad bastante alta y parece difícil de explotar. El parche se llama e748f43496d74946d14fed85c776452e47b99d64. Se recomienda aplicar un parche para solucionar este problema.

12 Jul 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-12 07:15

Updated : 2025-07-15 13:14


NVD link : CVE-2025-7464

Mitre link : CVE-2025-7464

CVE.ORG link : CVE-2025-7464


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read