Out-of-bounds read in FastNetMon - #VU138932

 

Out-of-bounds read in FastNetMon - #VU138932

Published: July 21, 2026


Vulnerability identifier: #VU138932
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service and disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the sFlow collector nested packet parser when processing a crafted sFlow v5 packet with an attacker-controlled header_size field. A remote attacker can send a specially crafted UDP packet to cause a denial of service and disclose sensitive information.

The issue occurs because the header_size field is trusted as the capture-length bound for nested Ethernet/IP/L4 parsing, causing bounds checks to use an attacker-inflated end pointer instead of the real buffer length.


Affected software

FastNetMon

Remediation

Cybersecurity Help is not aware of any official solution to address this vulnerability.


External References

Related Security Bulletins