CVE-2025-43970 Information

Description

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length e.g. by ensuring that there are 12 bytes or 36 bytes (depending on the address family).

Reference

https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0 https://github.com/osrg/gobgp/compare/v3.34.0…v3.35.0

Share on: