Bug 2467704 (CVE-2026-41643)

Summary: CVE-2026-41643 github.com/osrg/gobgp: GoBGP: Denial of Service via malformed BGP UPDATE message
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, abarbaro, abrianik, abuckta, akostadi, alizardo, amasferr, anthomas, ataylor, bbrownin, bdettelb, brasmith, cmah, cmyers, cochase, dbosanac, dbruscin, dfreiber, dkeler, dkuc, dmayorov, dnakabaa, doconnor, dranck, drow, dschmidt, dymurray, eaguilar, ebaron, eborisov, ehelms, ehugonne, ewittman, fmariani, ggainey, ggrzybek, gmalinko, gparvin, ibolton, janstey, jburrell, jchui, jhe, jkoehler, jlanda, jlledo, jmatthew, jmontleo, jolong, jpasqual, jraez, jreimann, juwatts, jwon, kaycoth, kshier, ktsao, kvanderr, lball, lchilton, lcouzens, lphiri, mcarlett, mdessi, mhulan, mrizzi, nboldt, ngough, nipatil, nmoumoul, oaljalju, orabin, osousa, pantinor, parichar, pcattana, pcreech, pgaikwad, pjindal, prwatson, psrna, rchan, rhaigner, rhel-process-autobot, rjohnson, rkubis, rstepani, sdawley, sfeifer, simaishi, slucidi, smallamp, sseago, stcannon, suppawar, tasato, tcunning, teagle, thason, tmalecek, tsedmik, veshanka, vkumar, watson-tool-maintainers, yfang, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in GoBGP. A remote attacker could send a specially crafted Border Gateway Protocol (BGP) UPDATE message that exploits improper handling of 4-byte Autonomous System (AS) attributes, causing an internal slice index shift. This leads to a runtime error, resulting in a Denial of Service (DoS) condition.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-07 13:01:35 UTC
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during the processing of 4-byte AS attributes when the message structure causes an internal slice index shift that is not properly handled. This issue has been patched in version 4.3.0.