Integer overflow in nfdump - #VU142752
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt parser state.
The vulnerability exists due to integer overflow in mplsLabelStack() and readExtendedVlanTunnel() in src/sflow/sflow_process.c when processing a crafted sFlow v5 extended data tag with an oversized depth field. A remote attacker can send a single crafted UDP packet to corrupt parser state.
The issue is reachable through the SFLFLOW_EX_MPLS and SFLFLOW_EX_VLAN_TUNNEL extended data tags.