GoBGP: BGP OPEN capability parser may read capability values outside declared CapLen boundaries
위협 신호 · CVSS · EPSS · KEV
정기 패치· 높은 악용 신호 없음
CVSS
5.9medium
이론적 심각도 점수
EPSS
—예측 데이터 없음
KEV
미등재실측 악용 기록 없음
권장 대응 기한60일 이내CISA SSVC 기준
계획된 패치 주기 내 조치(60일 이내)
외부 노출· KEV 미등재 · 자동화 어려움 · 부분 영향 · 외부 노출
CVSS 벡터 · 메트릭
악용 경로
공격 벡터네트워크
공격 복잡도높음
필요 권한불필요
사용자 상호작용불필요
범위불변
영향
기밀성 영향없음
무결성 영향높음
가용성 영향없음
버전별 점수
CVSS 3.15.9MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N상세 설명
Summary
text
1GoBGP contains a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the full remaining capability buffer instead of the slice bounded by the declared capability length, `CapLen`. 2A malformed BGP OPEN message can cause bytes from a following capability to be interpreted as part of the current capability. The most security-relevant case is the 4-octet AS capability, where a capability with `CapLen == 0` may cause the parser to read bytes from the following capability as the 4-octet AS value. This parsed value may later affect peer AS validation during BGP session establishment.Details
The issue is in the BGP OPEN capability parser under:
pkg/packet/bgp/bgp.gopkg/packet/bgp/validate.go
The BGP OPEN optional parameter capability format includes a capability code, a capability length field, and a capability value. Each concrete capability decoder should only parse bytes inside the declared capability value boundary.
In affected versions, the generic capability parser records the declared CapLen, but several concrete capability decoders continue parsing from the full remaining capability buffer after advancing past the two-byte capability header. Conceptually, the vulnerable pattern is:
bash
1data = data[2:] 2// decoder reads from data without first limiting it to CapLen 3 4### PoC 5The following parser-level proof of concept demonstrates the issue without requiring a full BGP session or a running `bgpd` instance. 6The malformed capability uses: 7- Capability Code: `65` (`BGP_CAP_FOUR_OCTET_AS_NUMBER`) 8- Declared `CapLen`: `0` 9- Four following bytes: `00 00 fd e8`10 11Although the capability declares an empty value, affected versions parse the following four bytes as the 4-octet AS value `65000`.12 13### Impact14A remote peer that can send a malformed BGP OPEN message to a GoBGP instance may cause capability values to be parsed from outside their declared `CapLen` boundaries.15In the 4-octet AS capability case, this may affect:16- peer AS validation;17- capability negotiation;18- interpretation of malformed OPEN messages;19- acceptance or rejection decisions during BGP session establishment.20This issue does not appear to be arbitrary memory corruption, remote code execution, or information disclosure. It is a protocol parser boundary validation issue that can affect BGP OPEN validation semantics.AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.