NULL pointer dereference in nfdump - #VU142745
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to null pointer dereference in ConvertRecordV2() in src/nfdump/compat_1_6_x/convert.c when processing a legacy v1.6.x block in which a CommonRecordType record appears before any ExtensionMapType record. A local user can supply a specially crafted file to cause a denial of service.
The issue affects the legacy v1.6.x block conversion path.