Race condition in FastNetMon - #VU138928

 

Race condition in FastNetMon - #VU138928

Published: July 21, 2026


Vulnerability identifier: #VU138928
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to concurrent execution using a shared resource with improper synchronization in the draw_table_ipv6() function and the ipv6_host_counters.average_speed_map when processing IPv6 NetFlow data while concurrently updating host counters. A remote attacker can send specially crafted NetFlow v9 traffic with many distinct IPv6 source addresses to cause a denial of service.

Exploitation requires the monitored networks configuration to include an IPv6 range covering the supplied addresses.


Affected software

FastNetMon

Remediation

Cybersecurity Help is not aware of any official solution to address this vulnerability.


External References

Related Security Bulletins