GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
02 / AFFECTED SOFTWARE
Affected packages
114 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function in github.com/osrg/gobgp
05 / REFERENCES
Further evidence
- https://github.com/osrg/gobgp
- https://github.com/osrg/gobgp/blob/v4.3.0/pkg/packet/bgp/bgp.go
- https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d
- https://nvd.nist.gov/vuln/detail/CVE-2026-37462
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/37xxx/CVE-2026-37462.json
- https://github.com/advisories/GHSA-pw7p-7fqv-hpj8