GoBGP vulnerabilities
Published: Wed, 03 Jun 2026 04:50
Summary
Several security issues were fixed in GoBGP.
Details
It was discovered that GoBGP incorrectly handled certain specially crafted BGP UPDATE messages. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-37461) Yanlei Wang discovered that GoBGP incorrectly handled certain malformed BGP UPDATE messages containing 4-byte AS attributes. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-41643) It was discovered that GoBGP incorrectly handled certain malformed BGP UPDATE messages containing SRv6 L3 Service attributes. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-7734) It was discovered that GoBGP incorrectly handled certain malformed BGP UPDATE messages containing Accumulated IGP (AIGP) attributes. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-7735) It was discovered that GoBGP incorrectly handled certain malformed Multi- threaded Routing Toolkit (MRT) routing information entries. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-7736) It was discovered that GoBGP incorrectly handled certain malformed Multi- threaded Routing Toolkit (MRT) headers. A remote attacker could possibly use this issue to cause GoBGP to crash, resulting in a denial of service. (CVE-2026-7737)
Recommended actions per Ubuntu release
StackPatch playbook auto-generated per release codename and per affected package.
Ubuntu bionic
gobgp→1.29-1ubuntu0.1+esm2apt_upgradeStandard apt upgrade. Install 1.29-1ubuntu0.1+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgp
Most apt upgrades restart their service automatically. needrestart lists anything else.
gobgpd→1.29-1ubuntu0.1+esm2apt_upgradeStandard apt upgrade. Install 1.29-1ubuntu0.1+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgpd
Most apt upgrades restart their service automatically. needrestart lists anything else.
golang-github-osrg-gobgp-dev→1.29-1ubuntu0.1+esm2apt_upgradeStandard apt upgrade. Install 1.29-1ubuntu0.1+esm2 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y golang-github-osrg-gobgp-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu focal
gobgp→2.12.0-1ubuntu0.1~esm3apt_upgrade_esmFixed at 2.12.0-1ubuntu0.1~esm3 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y gobgp=2.12.0-1ubuntu0.1~esm3
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
gobgpd→2.12.0-1ubuntu0.1~esm3apt_upgrade_esmFixed at 2.12.0-1ubuntu0.1~esm3 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y gobgpd=2.12.0-1ubuntu0.1~esm3
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
golang-github-osrg-gobgp-dev→2.12.0-1ubuntu0.1~esm3apt_upgrade_esmFixed at 2.12.0-1ubuntu0.1~esm3 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y golang-github-osrg-gobgp-dev=2.12.0-1ubuntu0.1~esm3
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
Ubuntu jammy
gobgp→2.25.0-3ubuntu0.1+esm4apt_upgradeStandard apt upgrade. Install 2.25.0-3ubuntu0.1+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgp
Most apt upgrades restart their service automatically. needrestart lists anything else.
gobgpd→2.25.0-3ubuntu0.1+esm4apt_upgradeStandard apt upgrade. Install 2.25.0-3ubuntu0.1+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgpd
Most apt upgrades restart their service automatically. needrestart lists anything else.
golang-github-osrg-gobgp-dev→2.25.0-3ubuntu0.1+esm4apt_upgradeStandard apt upgrade. Install 2.25.0-3ubuntu0.1+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y golang-github-osrg-gobgp-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu noble
gobgp→3.23.0-1ubuntu0.3+esm4apt_upgradeStandard apt upgrade. Install 3.23.0-1ubuntu0.3+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgp
Most apt upgrades restart their service automatically. needrestart lists anything else.
gobgpd→3.23.0-1ubuntu0.3+esm4apt_upgradeStandard apt upgrade. Install 3.23.0-1ubuntu0.3+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y gobgpd
Most apt upgrades restart their service automatically. needrestart lists anything else.
golang-github-osrg-gobgp-dev→3.23.0-1ubuntu0.3+esm4apt_upgradeStandard apt upgrade. Install 3.23.0-1ubuntu0.3+esm4 from the apt repo.
sudo apt-get update sudo apt-get install --only-upgrade -y golang-github-osrg-gobgp-dev
Most apt upgrades restart their service automatically. needrestart lists anything else.
Ubuntu resolute
gobgp→3.36.0-2ubuntu0.1~esm1apt_upgrade_esmFixed at 3.36.0-2ubuntu0.1~esm1 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y gobgp=3.36.0-2ubuntu0.1~esm1
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
gobgpd→3.36.0-2ubuntu0.1~esm1apt_upgrade_esmFixed at 3.36.0-2ubuntu0.1~esm1 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y gobgpd=3.36.0-2ubuntu0.1~esm1
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
golang-github-osrg-gobgp-dev→3.36.0-2ubuntu0.1~esm1apt_upgrade_esmFixed at 3.36.0-2ubuntu0.1~esm1 — ESM-only. Enable Ubuntu Pro (free for 5 personal machines) or treat as watch item.
sudo pro attach <token> sudo apt-get update sudo apt-get install --only-upgrade -y golang-github-osrg-gobgp-dev=3.36.0-2ubuntu0.1~esm1
Sign up at https://ubuntu.com/pro. Free for personal + small-team use.
Are YOU affected by USN-8348-1?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether USN-8348-1 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
StackPatch runs this match against YOUR installed packages every hour
Free 1-server / $99 lifetime founder seat (50 only) / $19+/mo monthly. Indie pricing.