An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Link | Tags |
---|---|
https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0 | patch release notes |
https://github.com/osrg/gobgp/commit/ca7383f450f7b296c5389feceef2467de5ab6e5a | patch |