CVE-2026-7737

NameCVE-2026-7737
DescriptionA vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gobgp (PTS)bullseye2.25.0-2vulnerable
bookworm3.10.0-1vulnerable
trixie3.36.0-2vulnerable
forky, sid4.4.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gobgpsource(unstable)4.4.0-1

Notes

Fixed by: https://github.com/osrg/gobgp/commit/bc77597d42335c78464bc8e15a471d887bbdf260 (v4.4.0)

Search for package or bug name: Reporting problems