CVE-2025-7464 Information
Jul 13, 2025
cve
Description
A vulnerability classified as problematic has been found in osrg GoBGP up to 3.37.0. Affected is the function SplitRTR of the file pkg/packet/rtr/rtr.go. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The name of the patch is e748f43496d74946d14fed85c776452e47b99d64. It is recommended to apply a patch to fix this issue.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Reference
https://github.com/osrg/gobgp/commit/e748f43496d74946d14fed85c776452e47b99d64 https://vuldb.com/?ctiid.316116 https://vuldb.com/?id.316116 https://vuldb.com/?submit.610193
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
LOW
Base Severity
3.7
Related CNNVD
CNNVD-202507-1720 (Published: 2025-07-12)
Share on: