HIGH8.6
GHSA-7m35-vw2c-696v
GoBGP panics due to a zero value for softwareVersionLen
Quick fix
GHSA-7m35-vw2c-696v — github.com/osrg/gobgp/v3: upgrade to the fixed version with the command below.
go get github.com/osrg/gobgp/v3@v3.35.0Details
An issue was discovered in GoBGP before 3.35.0 (introduced in v3.11.0). pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/osrg/gobgp/v3
Introduced in:
3.11.0Fixed in: 3.35.0Fix
go get github.com/osrg/gobgp/v3@v3.35.0References
- https://nvd.nist.gov/vuln/detail/CVE-2025-43971[ADVISORY]
- https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986[WEB]
- https://github.com/osrg/gobgp[PACKAGE]
- https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0[WEB]
- https://security-tracker.debian.org/tracker/CVE-2025-43971[WEB]