Out-of-bounds read in nfdump - #VU142757

 

Out-of-bounds read in nfdump - #VU142757

Published: August 15, 2026


Vulnerability identifier: #VU142757
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in decodeIPLayer4() in src/sflow/sflow_process.c when processing sFlow flow samples containing truncated TCP headers. A remote attacker can send a specially crafted sFlow flow sample to disclose sensitive information.

This issue occurs when the captured packet header is truncated near the start of the TCP header, such as with short snapshot lengths.


Affected software

nfdump

Remediation

Install security update from vendor's website.

nfdump - update to 1.7.9

External References

Related Security Bulletins