CVE-2026-42285
GoBGP has a panic in AdjRib.Update via malformed BGP Update message (Nil Pointer Dereference)
描述
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, an unauthenticated remote BGP peer can trigger a fatal panic in GoBGP by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a "withdraw" action, leading to a nil pointer dereference in the AdjRib.Update function. This causes the entire GoBGP process to crash, resulting in a complete loss of service availability. This issue has been patched in version 4.5.0.
如何修補 CVE-2026-42285
要修補 CVE-2026-42285,請將受影響套件升級到下列已修補版本。
- —升級至 4.5.0-1 或更新版本
- —升級至 4.5.0 或更新版本
CVE-2026-42285 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 4.5.0-1
- >= 4.4.0, < 4.5.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |