CVE-2023-46565
Publication date 29 April 2024
Last updated 22 July 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| gobgp | 26.04 LTS resolute |
Not affected
|
| 25.10 questing |
Not affected
|
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Fixed 2.25.0-3ubuntu0.1+esm2
|
|
| 20.04 LTS focal |
Fixed 2.12.0-1ubuntu0.1~esm2
|
|
| 18.04 LTS bionic | Ignored changes too intrusive |
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
shishirsub10
Multiple commits need to be backported to apply the fix in bionic which increases the chances of regression, hence it is ignored
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-7661-1
- GoBGP vulnerabilities
- 22 July 2025