SB20260721117 - Multiple vulnerabilities in FastNetMon
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Use-after-free (CVE-ID: N/A)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the NetFlow/IPFIX template cache when processing UDP flow data across multiple configured NetFlow/IPFIX listener ports. A remote attacker can send crafted NetFlow v9/IPFIX template redefinition and data packets to cause a denial of service.
Only deployments with more than one configured NetFlow/IPFIX listener port are vulnerable.
2) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the sFlow collector nested packet parser when processing a crafted sFlow v5 packet with an attacker-controlled header_size field. A remote attacker can send a specially crafted UDP packet to cause a denial of service and disclose sensitive information.
The issue occurs because the header_size field is trusted as the capture-length bound for nested Ethernet/IP/L4 parsing, causing bounds checks to use an attacker-inflated end pointer instead of the real buffer length.
3) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in parse_raw_packet_to_simple_packet_full() when parsing an IPv6 Fragment extension header. A remote attacker can send a specially crafted packet to disclose sensitive information and cause a denial of service.
The issue is reachable remotely and unauthenticated via a single crafted sFlow v5 UDP packet through RAW_PACKET_HEADER record handling.
4) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in netflow9_options_flowset_to_store() when processing the NETFLOW9_INTERFACE_DESCRIPTION field in NetFlow v9 packets. A remote attacker can send a specially crafted UDP packet to cause a denial of service.
The issue is reachable through the live UDP collector, and a single crafted packet without a null terminator in the interface-description field can trigger the crash.
5) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in parse_packet() in the pcap capture plugin when processing truncated captured frames. A remote attacker can send a specially crafted truncated frame to cause a denial of service.
Only deployments with pcap mode enabled are vulnerable.
6) Race condition (CVE-ID: N/A)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization in the draw_table_ipv6() function and the ipv6_host_counters.average_speed_map when processing IPv6 NetFlow data while concurrently updating host counters. A remote attacker can send specially crafted NetFlow v9 traffic with many distinct IPv6 source addresses to cause a denial of service.
Exploitation requires the monitored networks configuration to include an IPv6 range covering the supplied addresses.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.
References
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-ph88-95vc-x6gv
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-852r-3wcv-pjx2
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-jmjw-392h-4g93
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-ff5f-p5jw-8fq2
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-c27c-943r-vr8h
- https://github.com/pavel-odintsov/fastnetmon/security/advisories/GHSA-phrw-2q76-5m7h