GHSA-pw7p-7fqv-hpj8HighCVSS 7.3
GoBGP: Integer underflow in the BGPUpdate.DecodeFromBytes function
🔗 CVE IDs covered (1)
📋 Description
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
🎯 Affected products1
- go/github.com/osrg/gobgp/v4:< 4.4.0