Race condition in FastNetMon - #VU138928
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to concurrent execution using a shared resource with improper synchronization in the draw_table_ipv6() function and the ipv6_host_counters.average_speed_map when processing IPv6 NetFlow data while concurrently updating host counters. A remote attacker can send specially crafted NetFlow v9 traffic with many distinct IPv6 source addresses to cause a denial of service.
Exploitation requires the monitored networks configuration to include an IPv6 range covering the supplied addresses.