USN-8348-1: GoBGP vulnerabilities
It was discovered that GoBGP incorrectly handled certain specially crafted
BGP UPDATE messages. A remote attacker could possibly use this issue to
cause GoBGP to crash, resulting in a denial of service. (CVE-2026-37461)
Yanlei Wang discovered that GoBGP incorrectly handled certain malformed BGP
UPDATE messages containing 4-byte AS attributes. A remote attacker could
possibly use this issue to cause GoBGP to crash, resulting in a denial of
service. (CVE-2026-41643)
It was discovered that GoBGP incorrectly handled certain malformed BGP
UPDATE messages containing SRv6 L3 Service attributes. A remote attacker
could possibly use this issue to cause GoBGP to crash, resulting in a
denial of service. (CVE-2026-7734)
It was discovered that GoBGP incorrectly handled certain malformed BGP
UPDATE messages containing Accumulated IGP (AIGP) attributes. A remote
attacker could possibly use this issue to cause GoBGP to crash, resulting
in a denial of service. (CVE-2026-7735)
It was discovered that GoBGP incorrectly handled certain malformed Multi-
threaded Routing Toolkit (MRT) routing information entries. A remote
attacker could possibly use this issue to cause GoBGP to crash, resulting
in a denial of service. (CVE-2026-7736)
It was discovered that GoBGP incorrectly handled certain malformed Multi-
threaded Routing Toolkit (MRT) headers. A remote attacker could possibly
use this issue to cause GoBGP to crash, resulting in a denial of service.
(CVE-2026-7737)