CVE-2026-7734

EUVD-2026-26914
A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.88%
Affected Products (NVD)
VendorProductVersion
osrggobgp
𝑥
< 4.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gobgp
bookworm
postponed
bullseye
postponed
forky
4.7.0-1
fixed
sid
4.7.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gobgp
bionic
not-affected
focal
not-affected
jammy
Fixed 2.25.0-3ubuntu0.1+esm4
released
noble
Fixed 3.23.0-1ubuntu0.3+esm4
released
questing
ignored
resolute
Fixed 3.36.0-2ubuntu0.1~esm1
released