Out-of-bounds read in nfdump - #VU142753
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the sFlow 802.11 MAC parser when processing wireless bridge frames. A remote attacker can send a specially crafted sFlow record to disclose sensitive information.
Only 802.11 data frames with both ToDS and FromDS flags set trigger the read past the header boundary, and 6 bytes are copied into flow records where they remain visible to readers of the stored flow data.