---
title: "CVE-2025-7464\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2025-7464?format=md
keywords: index, follow
---

# CVE-2025-7464

Publication date 12 July 2025

Last updated 10 July 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.7 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2025-7464?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability classified as problematic has been found in osrg GoBGP up
to 3.37.0. Affected is the function SplitRTR of the file
pkg/packet/rtr/rtr.go. The manipulation leads to out-of-bounds read. It is
possible to launch the attack remotely. The complexity of an attack is
rather high. The exploitability is told to be difficult. The name of the
patch is e748f43496d74946d14fed85c776452e47b99d64. It is recommended to
apply a patch to fix this issue.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gobgp | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 25.04 plucky | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2025-7464?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| gobgp | * Upstream:   [e748f43](https://github.com/osrg/gobgp/commit/e748f43496d74946d14fed85c776452e47b99d64) |

## Severity score breakdown

CVSS version:

CVSS v4.0

[CVSS v4.0](https://ubuntu.com/security/CVE-2025-7464?format=md)
[CVSS v3.0](https://ubuntu.com/security/CVE-2025-7464?format=md)

**Base score**

6.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Attack requirements | None |
  | Privileges required | None |
  | User interaction | None |
  | Vulnerable system - Confidentiality impact | None |
  | Vulnerable system - Integrity impact | None |
  | Vulnerable system - Availability impact | Low |
  | Subsequent system - Confidentiality impact | None |
  | Subsequent system - Integrity impact | None |
  | Subsequent system - Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.3 · Medium |
  | Base + Threat score | - |
  | Base + Environmental score | - |
  | Base + Threat + Environmental score | - |

**Vector:** CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-7464)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-7464)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2025-7464)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2025-7464)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2025-7464>
* <https://vuldb.com/?ctiid.316116>
* <https://vuldb.com/?id.316116>
* <https://vuldb.com/?submit.610193>
