From d7d5a293a6ab9750fe2222a7e53df4fb177b1778 Mon Sep 17 00:00:00 2001 From: Shaked Shauli <127416012+shaked-seal@users.noreply.github.com> Date: Thu, 12 Mar 2026 13:34:16 +0200 Subject: [PATCH] Improve GHSA-7m35-vw2c-696v --- .../2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json b/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json index 962e74fac733f..9a69c49f79f46 100644 --- a/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json +++ b/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json @@ -7,7 +7,7 @@ "CVE-2025-43971" ], "summary": "GoBGP panics due to a zero value for softwareVersionLen", - "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.", + "details": "An issue was discovered in GoBGP before 3.35.0 (introduced in v3.11.0). pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.11.0" } ] } @@ -44,7 +44,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.11.0" }, { "fixed": "3.35.0"