CVE-2026-7737

EUVD-2026-26917
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component BMP Parser. The manipulation leads to out-of-bounds read. The attack can be initiated remotely. Upgrading to version 4.4.0 can resolve this issue. The identifier of the patch is bc77597d42335c78464bc8e15a471d887bbdf260. Upgrading the affected component is recommended.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 46.82%
Affected Products (NVD)
VendorProductVersion
osrggobgp
𝑥
< 4.4.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gobgp
bookworm
postponed
bullseye
postponed
forky
4.7.0-1
fixed
sid
4.7.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gobgp
bionic
Fixed 1.29-1ubuntu0.1+esm2
released
focal
Fixed 2.12.0-1ubuntu0.1~esm3
released
jammy
Fixed 2.25.0-3ubuntu0.1+esm4
released
noble
Fixed 3.23.0-1ubuntu0.3+esm4
released
questing
ignored
resolute
Fixed 3.36.0-2ubuntu0.1~esm1
released