CVE-2026-7734

NameCVE-2026-7734
DescriptionA vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gobgp (PTS)bullseye2.25.0-2vulnerable
bookworm3.10.0-1vulnerable
trixie3.36.0-2vulnerable
forky, sid4.5.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gobgpsource(unstable)4.4.0-1

Notes

[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
Fixed by: https://github.com/osrg/gobgp/commit/f9f7b55ec258e514be0264871fa645a2c3edad11 (v4.4.0)

Search for package or bug name: Reporting problems