An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0
https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0
Published: 2025-04-21
Updated: 2025-05-08
Named Vulnerability: GO-2025-3630Named Vulnerability: GHSA-hqhq-hp5x-xp3w
Base Score: 5
Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P
Severity: Medium
Base Score: 5.3
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity: Medium
EPSS: 0.00423