Out-of-bounds read in FastNetMon - #VU138929

 

Out-of-bounds read in FastNetMon - #VU138929

Published: July 21, 2026


Vulnerability identifier: #VU138929
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in parse_packet() in the pcap capture plugin when processing truncated captured frames. A remote attacker can send a specially crafted truncated frame to cause a denial of service.

Only deployments with pcap mode enabled are vulnerable.


Affected software

FastNetMon

Remediation

Cybersecurity Help is not aware of any official solution to address this vulnerability.


External References

Related Security Bulletins