Description
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument data[1] can lead to off-by-one. The attack may be launched remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. This patch is called 67c059413470df64bc20801c46f64058e88f800f. A patch should be applied to remediate this issue.
References (6)
Core 6
Core References
Product product
https://github.com/osrg/gobgp/
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-354155 | osrg GoBGP bgp.go DecodeFromBytes off-by-one
https://vuldb.com/vuln/354155
Signature, Permissions Required signature
permissions-required
VDB-354155 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/354155/cti
Third Party Advisory third-party-advisory
Submit #780179 | osrg GoBGP 4.3.0 Off-by-one Error
https://vuldb.com/submit/780179
Patch issue-tracking
patch
https://github.com/osrg/gobgp/pull/3342
Scores
CVSS v3
3.7
EPSS
0.0041
EPSS Percentile
32.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-189
CWE-193
Status
published
Products (5)
osrg/gobgp
< 4.4.0
osrg/GoBGP
4.0
osrg/GoBGP
4.1
osrg/GoBGP
4.2
osrg/GoBGP
4.3.0
Published
Mar 30, 2026
Tracked Since
Mar 30, 2026