Bug#1109300: gobgp: CVE-2025-7464

2025-07-15 Thread Salvatore Bonaccorso
Hi Mathias, On Tue, Jul 15, 2025 at 09:33:21AM +, Mathias Gibbens wrote: > AI-generated slop CVE originating from "CyberGym"[0,1]. Oh well. > Claimed fix of the issue has been committed upstream for over a month > and will be part of the next release. Until/unless upstream says > otherwi

Bug#1109300: gobgp: CVE-2025-7464

2025-07-15 Thread Mathias Gibbens
AI-generated slop CVE originating from "CyberGym"[0,1]. Claimed fix of the issue has been committed upstream for over a month and will be part of the next release. Until/unless upstream says otherwise, I don't see justification for the Security Team to waste any time on this. Mathias [0] --

Bug#1109300: gobgp: CVE-2025-7464

2025-07-14 Thread Salvatore Bonaccorso
Source: gobgp Version: 3.36.0-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for gobgp. CVE-2025-7464[0]: | A vulnerability classified as problematic has been found in osrg | GoBGP up to 3.37.0. A