Vulnerabilities > CVE-2025-43970 - Improper Validation of Specified Quantity in Input vulnerability in Osrg Gobgp

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
LOW
network
low complexity
osrg
CWE-1284

Summary

An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).

Vulnerable Configurations

Part Description Count
Application
Osrg
108