PT-2026-37259 · Gobgp+1 · Gobgp+1

·

CVE-2026-42285

·

Published

2026-05-01

·

Updated

2026-08-19

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GoBGP versions prior to 4.5.0
Description An unauthenticated remote BGP peer can cause a fatal panic and complete loss of service availability by sending a specially crafted BGP UPDATE message. When the server receives a message with inconsistent attribute lengths, it improperly handles the internal state transition to a withdraw action. This leads to a nil pointer dereference—a situation where the software attempts to access a memory location that does not exist—within the AdjRib.Update() function. The issue originates from the interaction between the BGP message decoding logic and the Adj-RIB table management, specifically when the handleUpdate function processes malformed attributes.
Recommendations Update to version 4.5.0.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14525
CVE-2026-42285
GHSA-P3W2-64XM-833J
GO-2026-5525
OPENSUSE-SU-2026:21551-1
SUSE-SU-2026:23216-1
SUSE-SU-2026:23227-1

Affected Products

Gobgp
Red Os