Integer overflow in nfdump - #VU142748
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in Process_v9_option_templates() in src/netflow/netflow_v9.c when processing NetFlow v9 option templates. A remote attacker can send a specially crafted UDP packet to cause a denial of service.
The issue can also cause heap data to be read beyond the allocation boundary and written into nbar or ifvrf flow records stored on disk.