Out-of-bounds read in FastNetMon - #VU138930
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in netflow9_options_flowset_to_store() when processing the NETFLOW9_INTERFACE_DESCRIPTION field in NetFlow v9 packets. A remote attacker can send a specially crafted UDP packet to cause a denial of service.
The issue is reachable through the live UDP collector, and a single crafted packet without a null terminator in the interface-description field can trigger the crash.