Integer overflow in nfdump - #VU142755
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause corrupted flow records.
The vulnerability exists due to integer overflow in the sFlow extended gateway communities parser when parsing a crafted sFlow packet. A remote attacker can supply a crafted communities length value to misalign subsequent parsing and cause corrupted flow records.
In DEVEL builds, the issue can also trigger an out-of-bounds read that may crash the process.