CVE-2026-7736

EUVD-2026-26916
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer underflow. It is possible to launch the attack remotely. Upgrading to version 4.4.0 addresses this issue. This patch is called 76d911046344a3923cbe573364197aa081944592. It is suggested to upgrade the affected component.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.3 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.23%
Affected Products (NVD)
VendorProductVersion
osrggobgp
𝑥
< 4.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gobgp
bookworm
postponed
bullseye
postponed
forky
4.7.0-1
fixed
sid
4.7.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gobgp
bionic
Fixed 1.29-1ubuntu0.1+esm2
released
focal
Fixed 2.12.0-1ubuntu0.1~esm3
released
jammy
Fixed 2.25.0-3ubuntu0.1+esm4
released
noble
Fixed 3.23.0-1ubuntu0.3+esm4
released
questing
ignored
resolute
Fixed 3.36.0-2ubuntu0.1~esm1
released
Common Weakness Enumeration