Out-of-bounds read in FastNetMon - #VU138931
Published: July 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in parse_raw_packet_to_simple_packet_full() when parsing an IPv6 Fragment extension header. A remote attacker can send a specially crafted packet to disclose sensitive information and cause a denial of service.
The issue is reachable remotely and unauthenticated via a single crafted sFlow v5 UDP packet through RAW_PACKET_HEADER record handling.